--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c3af1a6b23
2026-01-08 01:26:39.511509+00:00
--------------------------------------------------------------------------------

Name        : selinux-policy
Product     : Fedora 43
Version     : 42.20
Release     : 1.fc43
URL         : https://github.com/fedora-selinux/selinux-policy
Summary     : SELinux policy configuration
Description :
SELinux core policy package.
Originally based off of reference policy,
the policy has been adjusted to provide support for Fedora.

--------------------------------------------------------------------------------
Update Information:

New F43 selinux-policy build
--------------------------------------------------------------------------------
ChangeLog:

* Fri Dec 19 2025 Zdenek Pytela <[email protected]> - 42.20-1
- Support cockpit privileged access for the staff user
- Update su_domain_type policy for kerberized su
- Allow sshd-session inherit limits from its parent process
- Allow systemd-machined read virtd process state
- Allow kl2tpd create and use netlink_generic_socket
- Update policy for redfish-finder
- Label the greetd login manager framework as a display manager
- Allow sshd-auth get attributes of sshd vsock socket
- Confine redfish_finder - host api discovery service
- Allow iptables read firewalld process state
- Allow tuned_t use its private tmpfs files
- The commit addresses the following AVC denials:
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2418343 - AVC denial triggered for coredump in a container
        https://bugzilla.redhat.com/show_bug.cgi?id=2418343
  [ 2 ] Bug #2419755 - SELinux is preventing blocking-2 from 'write' accesses 
on the sock_file org.gnome.DisplayManager.
        https://bugzilla.redhat.com/show_bug.cgi?id=2419755
  [ 3 ] Bug #2423556 - SELinux is preventing irqbalance from 'create' accesses 
on the netlink_generic_socket labeled irqbalance_t.
        https://bugzilla.redhat.com/show_bug.cgi?id=2423556
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c3af1a6b23' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to