-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c3af1a6b23 2026-01-08 01:26:39.511509+00:00 --------------------------------------------------------------------------------
Name : selinux-policy Product : Fedora 43 Version : 42.20 Release : 1.fc43 URL : https://github.com/fedora-selinux/selinux-policy Summary : SELinux policy configuration Description : SELinux core policy package. Originally based off of reference policy, the policy has been adjusted to provide support for Fedora. -------------------------------------------------------------------------------- Update Information: New F43 selinux-policy build -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 19 2025 Zdenek Pytela <[email protected]> - 42.20-1 - Support cockpit privileged access for the staff user - Update su_domain_type policy for kerberized su - Allow sshd-session inherit limits from its parent process - Allow systemd-machined read virtd process state - Allow kl2tpd create and use netlink_generic_socket - Update policy for redfish-finder - Label the greetd login manager framework as a display manager - Allow sshd-auth get attributes of sshd vsock socket - Confine redfish_finder - host api discovery service - Allow iptables read firewalld process state - Allow tuned_t use its private tmpfs files - The commit addresses the following AVC denials: -------------------------------------------------------------------------------- References: [ 1 ] Bug #2418343 - AVC denial triggered for coredump in a container https://bugzilla.redhat.com/show_bug.cgi?id=2418343 [ 2 ] Bug #2419755 - SELinux is preventing blocking-2 from 'write' accesses on the sock_file org.gnome.DisplayManager. https://bugzilla.redhat.com/show_bug.cgi?id=2419755 [ 3 ] Bug #2423556 - SELinux is preventing irqbalance from 'create' accesses on the netlink_generic_socket labeled irqbalance_t. https://bugzilla.redhat.com/show_bug.cgi?id=2423556 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c3af1a6b23' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
