Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The policycoreutils packages contain the core policy utilities required to
manage a SELinux environment.
Security Fix(es):
* It was found that the sandbox tool provided in policycoreutils was
vulnerable to a TIOCSTI ioctl attack. A specially crafted program executed
via the sandbox command could use this flaw to execute arbitrary commands
in the context of the parent shell, escaping the sandbox. (CVE-2016-7545)
https://access.redhat.com/security/cve/CVE-2016-7545 https://access.redhat.com/security/updates/classification/#important
Red Hat Enterprise Linux ComputeNode EUS (v. 7.2):
Source:
policycoreutils-2.2.5-21.el7_2.src.rpm
x86_64:
policycoreutils-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-debuginfo-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-newrole-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-python-2.2.5-21.el7_2.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.2):
x86_64:
policycoreutils-debuginfo-2.2.5-21.el7_2.i686.rpm
policycoreutils-debuginfo-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-devel-2.2.5-21.el7_2.i686.rpm
policycoreutils-devel-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-gui-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-restorecond-2.2.5-21.el7_2.x86_64.rpm
policycoreutils-sandbox-2.2.5-21.el7_2.x86_64.rpm
Red Hat Enterprise Linux Server EUS (v. 7.2):
Source:
policycoreutils-2.2.5-21.el7_2.src.rpm
ppc64:
policycoreutils-2.2.5-21.el7_2.ppc64.rpm
policycoreutils-debuginfo-2.2.5-21.el7_2.ppc.rpm
policycoreutils-debuginfo-2.2.5-21.el7_2.ppc64.rpm
policycoreutils-devel-2.2.5-21.el7_2.ppc.rpm
policycoreutils-devel-2.2.5-21.el7_2.ppc64.rpm
policycoreutils-gui-2.2.5-21.el7_2.ppc64.rpm
policycoreutils-newrole-2.2.5-21.el7_2.ppc64.rpm
policycoreutils-python-2.2.5-21.el7_2.ppc64.rpm
policycoreutils-sandbox-2.2.5-21.el7_2.ppc64.rpm
ppc64le:
policycoreutils-2.2.5-21.el7_2.ppc64le.rpm
Read the Full Advisory
An update for policycoreutils is now available for Red Hat Enterprise Linux7.2 Extended Update Support.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux ComputeNode EUS (v. 7.2) - x86_64
Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.2) - x86_64
Red Hat Enterprise Linux Server EUS (v. 7.2) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional EUS (v. 7.2) - ppc64, ppc64le, s390x, x86_64
1378577 - CVE-2016-7545 policycoreutils: SELinux sandbox escape via TIOCSTI ioctl
Get the latest Linux and open source security news straight to your inbox.