-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a84432e770 2025-05-14 01:19:17.147876+00:00 --------------------------------------------------------------------------------
Name : selinux-policy Product : Fedora 41 Version : 41.39 Release : 1.fc41 URL : https://github.com/fedora-selinux/selinux-policy Summary : SELinux policy configuration Description : SELinux core policy package. Originally based off of reference policy, the policy has been adjusted to provide support for Fedora. -------------------------------------------------------------------------------- Update Information: New F41 selinux-policy build -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 30 2025 Zdenek Pytela <[email protected]> - 41.39-1 - Allow collectd accept and listen to tcp sockets - Allow init_t nnp domain transition to redis_t - Allow tlshd read network sysctls - Allow NetworkManager create and use icmp_socket - Allow varnishd execute the prlimit64() syscall - Allow rhsmcertd connect to systemd-machined - Allow virt_domain write to virt_image_t files - Allow system-dbusd list systemd-machined directories - Allow asterisk read network sysctls - Allow virtstoraged fsetid capability - Allow xdm watch a mnt_t directory - Allow collectd bind TCP sockets to the collectd port - Allow virtqemud relabel from tmpfs lnk files - Allow gnome-remote-desktop additional sockets permissions - Update insights-core policy - Update systemd-homed policy - Allow xenstored_t manage xend_var_lib_t files (bsc#1228540) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2322867 - selinux policy violations when asterisk tries to read /proc/sys/net https://bugzilla.redhat.com/show_bug.cgi?id=2322867 [ 2 ] Bug #2354219 - SELinux is preventing gnome-session-b from 'watch' accesses on the directory /run/media. (excessive spam and notification spam as well, 20fps on the desktop on a 4070TI) https://bugzilla.redhat.com/show_bug.cgi?id=2354219 [ 3 ] Bug #2354857 - SELinux is preventing /usr/sbin/collectd from name_bind access on the tcp_socket port 9103 https://bugzilla.redhat.com/show_bug.cgi?id=2354857 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a84432e770' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
