New F39 selinux-policy build. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-334b3be641 2024-01-30 04:21:41.500079 -------------------------------------------------------------------------------- Name : selinux-policy Product : Fedora 39 Version : 39.4 Release : 1.fc39 URL : https://github.com/fedora-selinux/selinux-policy Summary : SELinux policy configuration Description : SELinux core policy package. Originally based off of reference policy, the policy has been adjusted to provide support for Fedora. -------------------------------------------------------------------------------- Update Information: New F39 selinux-policy build -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 25 2024 Zdenek Pytela - 39.4-1 - Allow collectd read raw fixed disk device - Allow collectd read udev pid files - Allow httpd work with PrivateTmp - Allow certmonger read network sysctls - Allow systemd-sleep set attributes of efivarfs files - Allow spamd_update_t the sys_ptrace capability in user namespace - Allow alsa get attributes filesystems with extended attributes - Allow systemd-sleep send a message to syslog over a unix dgram socket -------------------------------------------------------------------------------- References: [ 1 ] Bug #2249960 - SELinux is preventing rm from getattr access on the filesystem /. https://bugzilla.redhat.com/show_bug.cgi?id=2249960 [ 2 ] Bug #2252484 - avc denials policykit_auth_t policykit_t spamd_update_t Fedora 39 https://bugzilla.redhat.com/show_bug.cgi?id=2252484 [ 3 ] Bug #2255693 - SELinux is preventing systemd-sleep from setattr access on the file /sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67. https://bugzilla.redhat.com/show_bug.cgi?id=2255693 [ 4 ] Bug #2258637 - [selinux] systemd cannot flush the privatetmp cache usedby php-fpm https://bugzilla.redhat.com/show_bug.cgi?id=2258637 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-334b3be641' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The previous Imagemagick security update caused a regression in some perl packages due to overly restrictive hardening in a policy update (reading from /etc/ was forbidden). This hardening patch has been removed. . From: imagemagick To:
Use a more restrictive blacklist in several policy abstractions.. =========================================================================Ubuntu Security Notice USN-3784-1 October 04, 2018 AppArmor update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Use a more restrictive blacklist in several policy abstractions. Software Description: - apparmor: Linux security system Details: As a security improvement, this update adjusts the private-files abstraction to disallow writing to thumbnailer configuration files. Additionally adjust the private-files, private-files-strict and user-files abstractions to disallow writes on parent directories of sensitive files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: apparmor 2.12-4ubuntu5.1 Ubuntu 16.04 LTS: apparmor 2.10.95-0ubuntu2.10 Ubuntu 14.04 LTS: apparmor 2.10.95-0ubuntu2.6~14.04.4 In general, a standard system update will make all the necessary changes. References: https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1788929, https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1794848 Package Information: https://launchpad.net/ubuntu/+source/apparmor/2.12-4ubuntu5.1 https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.10 https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.4 . The Ubuntu Security Notice USN-3784-1 outlines a significant AppArmor enhancement aimed at bolstering security in various Ubuntu LTS distributions.. AppArmor Update, Ubuntu Security Notice, Policy Adjustments. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.