New F31 selinux-policy build. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-b2d6cffc6f 2020-09-12 16:36:51.588528 --------------------------------------------------------------------------------Name : selinux-policy Product : Fedora 31 Version : 3.14.4 Release : 54.fc31 URL : https://github.com/fedora-selinux/selinux-policy Summary : SELinux policy configuration Description : SELinux Base package for SELinux Reference Policy - modular. Based off of reference policy: Checked out revision 2.20091117 --------------------------------------------------------------------------------Update Information: New F31 selinux-policy build --------------------------------------------------------------------------------ChangeLog: * Thu Aug 27 2020 Zdenek Pytela - 3.14.4-54 - Allow munin domain transition with NoNewPrivileges - Allow syslogd_t domain to read/write tmpfs systemd-bootchart files - Allow unconfined_t to node_bind icmp_sockets in node_t domain - Change transitions for ~/.config/Yubico - Add file context for ~/.config/Yubico - Create macro corenet_icmp_bind_generic_node() - Allow traceroute_t and ping_t to bind generic nodes. - Allow systemd set efivarfs files attributes - Split the arping path regexp to 2 lines to prevent from relabeling --------------------------------------------------------------------------------References: [ 1 ] Bug #1775780 - SELinux is preventing systemd from 'setattr' accesses on the file LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. https://bugzilla.redhat.com/show_bug.cgi?id=1775780 [ 2 ] Bug #1857381 - munin is generating an avc denial when trying to access /usr/bin/munin-cron https://bugzilla.redhat.com/show_bug.cgi?id=1857381 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-b2d6cffc6f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New F33 selinux-policy build.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-8f3381648b 2020-09-02 15:41:58.309847 --------------------------------------------------------------------------------Name : selinux-policy Product : Fedora 33 Version : 3.14.6 Release : 25.fc33 URL : https://github.com/fedora-selinux/selinux-policy Summary : SELinux policy configuration Description : SELinux Base package for SELinux Reference Policy - modular. Based off of reference policy: Checked out revision 2.20091117 --------------------------------------------------------------------------------Update Information: New F33 selinux-policy build. --------------------------------------------------------------------------------ChangeLog: * Thu Aug 27 2020 Zdenek Pytela - 3.14.6-25 - Allow certmonger fowner capability - The nfsdcld service is now confined by SELinux - Change transitions for ~/.config/Yubico - Allow all users to connect to systemd-userdbd with a unix socket - Add file context for ~/.config/Yubico - Allow syslogd_t domain to read/write tmpfs systemd-bootchart files - Allow login_pgm attribute to get attributes in proc_t - Allow passwd to get attributes in proc_t - Revert "Allow passwd to get attributes in proc_t" - Revert "Allow login_pgm attribute to get attributes in proc_t" - Allow login_pgm attribute to get attributes in proc_t - Allow passwd to get attributes in proc_t - Allow traceroute_t and ping_t to bind generic nodes. - Create macro corenet_icmp_bind_generic_node() - Allow unconfined_t to node_bind icmp_sockets in node_t domain --------------------------------------------------------------------------------References: [ 1 ] Bug #1848929 - ping causes AVC https://bugzilla.redhat.com/show_bug.cgi?id=1848929 [ 2 ] Bug #1853730 - Multiple "denied { getattr } for pid=856 comm="login" name="/" dev="proc"" AVCs with Fedora-Rawhide-20200703.n.0 https://bugzilla.redhat.com/show_bug.cgi?id=1853730 [ 3 ] Bug #1865748 - SELinux prevents systemd-nspawn from launching a machine https://bugzilla.redhat.com/show_bug.cgi?id=1865748 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-8f3381648b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-486 2005-06-29 ---------------------------------------------------------------------Product : Fedora Core 3 Name : selinux-policy-targeted Version : 1.17.30 Release : 3.15 Summary : SELinux targeted policy configuration Description : Security-enhanced Linux is a patch of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. This package contains the SELinux example policy configuration along with the Flask configuration information and the application configuration files. ---------------------------------------------------------------------* Sat Jun 25 2005 Dan Walsh 1.17.30-3.15 - Fix /opt definition ---------------------------------------------------------------------This update can be downloaded from: 81510077d91fb4c998301099da3afd8d SRPMS/selinux-policy-targeted-1.17.30-3.15.src.rpm 98bab0bbced70538816a0fd882f6e030 x86_64/selinux-policy-targeted-1.17.30-3.15.noarch.rpm 6dac1b5095128c1c9ce03426eb74ba3b x86_64/selinux-policy-targeted-sources-1.17.30-3.15.noarch.rpm 98bab0bbced70538816a0fd882f6e030 i386/selinux-policy-targeted-1.17.30-3.15.noarch.rpm 6dac1b5095128c1c9ce03426eb74ba3b i386/selinux-policy-targeted-sources-1.17.30-3.15.noarch.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- --fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-413 2005-06-16 ---------------------------------------------------------------------Product : Fedora Core 3 Name : selinux-policy-targeted Version : 1.17.30 Release : 3.9 Summary : SELinux targeted policy configuration Description : Security-enhanced Linux is a patch of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. This package contains the SELinux example policy configuration along with the Flask configuration information and the application configuration files. ---------------------------------------------------------------------* Mon Jun 13 2005 Dan Walsh 1.17.30-3.9 - Allow unconfined_t full execmod access. * Fri Jun 10 2005 Dan Walsh 1.17.30-3.8 - Add daemon attribute to daemon_core_domain to make nscd work correctly * Thu Jun 9 2005 Dan Walsh 1.17.30-3.7 - Merge to upstream release * Thu May 12 2005 Dan Walsh 1.17.30-3.6 - Make work on RHEL * Thu May 12 2005 Dan Walsh 1.17.30-3.5 - Merge to upstream release * Mon May 9 2005 Dan Walsh 1.17.30-3.4 - Default httpd_builtin_scripting to true. * Sat May 7 2005 Dan Walsh 1.17.30-3.3 - Add file context for /usr/local/*.so files * Thu May 5 2005 Dan Walsh 1.17.30-3.2 - Update unconfined_t to use proc_net ---------------------------------------------------------------------This update can be downloaded from: 286b333e6f3cd9c91f0008950b4f5f83 SRPMS/selinux-policy-targeted-1.17.30-3.9.src.rpm 3db734679faa2b2f90d05c3fecbfe8e8 x86_64/selinux-policy-targeted-1.17.30-3.9.noarch.rpm 02bbe247feb660e7c17e0cfca5e9c788 x86_64/selinux-policy-targeted-sources-1.17.30-3.9.noarch.rpm 3db734679faa2b2f90d05c3fecbfe8e8 i386/selinux-policy-targeted-1.17.30-3.9.noarch.rpm 02bbe247feb660e7c17e0cfca5e9c788 i386/selinux-policy-targeted-sources-1.17.30-3.9.noarch.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- --fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-278 2005-04-08 ---------------------------------------------------------------------Product : Fedora Core 3 Name : selinux-policy-targeted Version : 1.17.30 Release : 2.94 Summary : SELinux targeted policy configuration Description : Security-enhanced Linux is a patch of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. This package contains the SELinux example policy configuration along with the Flask configuration information and the application configuration files. ---------------------------------------------------------------------* Wed Mar 30 2005 Dan Walsh 1.17.30-2.94 - Prepare policy for kernel rebase ---------------------------------------------------------------------This update can be downloaded from: 174eb7e9bfa98578a56ac95927d7b6f6 SRPMS/selinux-policy-targeted-1.17.30-2.94.src.rpm 484882f088b7c9c4273e56131dece456 x86_64/selinux-policy-targeted-1.17.30-2.94.noarch.rpm 16219038ff05847d19d7295685b28d86 x86_64/selinux-policy-targeted-sources-1.17.30-2.94.noarch.rpm 484882f088b7c9c4273e56131dece456 i386/selinux-policy-targeted-1.17.30-2.94.noarch.rpm 16219038ff05847d19d7295685b28d86 i386/selinux-policy-targeted-sources-1.17.30-2.94.noarch.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. ----------------------------------------------------------------------- --fedora-announce-list mailing list
Updated packages.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-150 2005-02-26 ---------------------------------------------------------------------Product : Fedora Core 3 Name : selinux-policy-targeted Version : 1.17.30 Release : 2.83 Summary : SELinux targeted policy configuration Description : Security-enhanced Linux is a patch of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. This package contains the SELinux example policy configuration along with the Flask configuration information and the application configuration files. ---------------------------------------------------------------------* Thu Feb 17 2005 Dan Walsh 1.17.30-2.83 - Allow squirrelmail check spelling to work * Wed Feb 9 2005 Dan Walsh 1.17.30-2.81 - Allow syslog to use @host and | commands ---------------------------------------------------------------------This update can be downloaded from: 9547bb431136e67aa134daed5b0271bb SRPMS/selinux-policy-targeted-1.17.30-2.83.src.rpm 9c98cb1f2dc6c468db8a0358ea0cae5f x86_64/selinux-policy-targeted-1.17.30-2.83.noarch.rpm 2e60bf1fcd0bc4e85e45dcc8b4d68908 x86_64/selinux-policy-targeted-sources-1.17.30-2.83.noarch.rpm 9c98cb1f2dc6c468db8a0358ea0cae5f i386/selinux-policy-targeted-1.17.30-2.83.noarch.rpm 2e60bf1fcd0bc4e85e45dcc8b4d68908 i386/selinux-policy-targeted-sources-1.17.30-2.83.noarch.rpm This update can also be installed with the Update Agent; you can launch the UpdateAgent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Allow ldconfig to run with full privs.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-006 2005-01-07 ---------------------------------------------------------------------Product : Fedora Core 3 Name : selinux-policy-targeted Version : 1.17.30 Release : 2.68 Summary : SELinux targeted policy configuration Description : Security-enhanced Linux is a patch of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. This package contains the SELinux example policy configuration along with the Flask configuration information and the application configuration files. ---------------------------------------------------------------------Update Information: Allow ldconfig to run with full privs. ------------------------------------------------------------------------------------------------------------------------------------------This update can be downloaded from: e7e8084a84fbf62a0f8acd5c37d81385 SRPMS/selinux-policy-targeted-1.17.30-2.68.src.rpm c1c3835aafc1cbd72a59645ac6377ca1 x86_64/selinux-policy-targeted-1.17.30-2.68.noarch.rpm 32a415a052893814fb3e32a7f1f59736 x86_64/selinux-policy-targeted-sources-1.17.30-2.68.noarch.rpm c1c3835aafc1cbd72a59645ac6377ca1 i386/selinux-policy-targeted-1.17.30-2.68.noarch.rpm 32a415a052893814fb3e32a7f1f59736 i386/selinux-policy-targeted-sources-1.17.30-2.68.noarch.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. -----------------------------------------------------------------------fedora-announce-list mailing list
Fix for postgres startup scripts.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-580 2004-12-31 ---------------------------------------------------------------------Product : Fedora Core 3 Name : selinux-policy-targeted Version : 1.17.30 Release : 2.62 Summary : SELinux targeted policy configuration Description : Security-enhanced Linux is a patch of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. This package contains the SELinux example policy configuration along with the Flask configuration information and the application configuration files. ---------------------------------------------------------------------Update Information: Fix for postgres startup scripts. ---------------------------------------------------------------------* Thu Dec 30 2004 Dan Walsh 1.17.30-2.62 - Allow postgres to exec itself ---------------------------------------------------------------------This update can be downloaded from: 4076a42bc1657fa8503aa9c9c4bff616 SRPMS/selinux-policy-targeted-1.17.30-2.62.src.rpm 176a3cab6d17253b329b82f2aba8779b x86_64/selinux-policy-targeted-1.17.30-2.62.noarch.rpm 52131939deec8836cf4f0b3f85768bd3 x86_64/selinux-policy-targeted-sources-1.17.30-2.62.noarch.rpm 176a3cab6d17253b329b82f2aba8779b i386/selinux-policy-targeted-1.17.30-2.62.noarch.rpm 52131939deec8836cf4f0b3f85768bd3 i386/selinux-policy-targeted-sources-1.17.30-2.62.noarch.rpm This update can also be installed with the UpdateAgent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.