Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 33 SELinux Policy Update 2020-8f3381648b: Important Security Fixes

fedora
Calendar Grey September 2, 2020
Dist Fedora Esm H88
The latest SELinux policy revision for Fedora 33 incorporates essential enhancements that bolster security features and optimize system efficiency.
New F33 selinux-policy build.

Summary

SELinux Base package for SELinux Reference Policy - modular.

Based off of reference policy: Checked out revision 2.20091117

New F33 selinux-policy build.

* Thu Aug 27 2020 Zdenek Pytela - 3.14.6-25

- Allow certmonger fowner capability

- The nfsdcld service is now confined by SELinux

- Change transitions for ~/.config/Yubico

- Allow all users to connect to systemd-userdbd with a unix socket

- Add file context for ~/.config/Yubico

- Allow syslogd_t domain to read/write tmpfs systemd-bootchart files

- Allow login_pgm attribute to get attributes in proc_t

- Allow passwd to get attributes in proc_t

- Revert "Allow passwd to get attributes in proc_t"

- Revert "Allow login_pgm attribute to get attributes in proc_t"

- Allow login_pgm attribute to get attributes in proc_t

- Allow passwd to get attributes in proc_t

- Allow traceroute_t and ping_t to bind generic nodes.

- Create macro corenet_icmp_bind_generic_node()

- Allow unconfined_t to node_bind icmp_sockets in node_t domain

[ 1 ] Bug #1848929 - ping causes AVC

https://bugzilla.redhat.com/show_bug.cgi?id=1848929

[ 2 ] Bug #1853730 - Multiple "denied { getattr } for pid=856 comm="login" name="/" dev="proc"" AVCs with Fedora-Rawhide-20200703.n.0

https://bugzilla.redhat.com/show_bug.cgi?id=1853730

[ 3 ] Bug #1865748 - SELinux prevents systemd-nspawn from launching a machine

https://bugzilla.redhat.com/show_bug.cgi?id=1865748

su -c 'dnf upgrade --advisory FEDORA-2020-8f3381648b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 3.14.6
Release: 25.fc33
Summary: SELinux policy configuration

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here