- Issued:
- 2010-01-07
- Updated:
- 2010-01-07
RHBA-2010:0013 - Bug Fix Advisory
Synopsis
selinux-policy bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated selinux-policy packages that fix several bugs are now available.
Description
The selinux-policy packages contain the rules that govern how confined
processes run on the system.
These updated selinux-policy packages provide fixes for the following bugs:
- the "setkey" utility from the ipsec-tools package manipulates and dumps
the kernel's Security Policy Database (SPD) entries and Security
Association Database (SAD) entries. The current selinux-policy did not
allow users running under the "sysadm" role to use setkey. This update
allows users running under the sysadm SELinux role to use the setkey
utility from the ipsec-tools package. (BZ#538449)
- using the Openswan implementation of IPsec could have resulted in AVC
(Access Vector Cache) denials causing the integrity check to fail, which in
turn would cause the pluto key management daemon not to start. This update
includes updated policy rules for IPsec which fix the AVC denials so that
pluto is allowed to run as expected. Note that this is necessary for
FIPS-140 compliance. (BZ#538452)
- SELinux denials caused by the ssh-keygen's
"system_u:object_r:initrc_exec_t" context caused ssh-keygen to fail to
generate public/private RSA key pairs. These updated SELinux policy rules
allow ssh-keygen to successfully generate public/private RSA key pairs as
expected. (BZ#538453)
- when the "ifup" script was run manually in order to activate the first
IPsec interface, which then attempts to start racoon, racoon incorrectly
ran under the "unconfined_t" context instead of under the expected
"racoon_t", thus preventing it from starting. Note that this did not happen
when the IPsec network interface configuration file contained an
"ONBOOT=yes" parameter; racoon successfully started in this case. With this
update, racoon possesses the correct context, "racoon_t", which allows it
to run when started via the ifup network startup script. (BZ#538503)
All users are advised to upgrade to these updated packages,
which resolve these issues.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
Affected Products
- Red Hat Enterprise Linux Server 5 x86_64
- Red Hat Enterprise Linux Server 5 ia64
- Red Hat Enterprise Linux Server 5 i386
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 5.4 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 5.4 ia64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 5.4 i386
- Red Hat Enterprise Linux Workstation 5 x86_64
- Red Hat Enterprise Linux Workstation 5 i386
- Red Hat Enterprise Linux Desktop 5 x86_64
- Red Hat Enterprise Linux Desktop 5 i386
- Red Hat Enterprise Linux for IBM z Systems 5 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 5.4 s390x
- Red Hat Enterprise Linux for Power, big endian 5 ppc
- Red Hat Enterprise Linux for Power, big endian - Extended Update Support 5.4 ppc
- Red Hat Enterprise Linux Server from RHUI 5 x86_64
- Red Hat Enterprise Linux Server from RHUI 5 i386
Fixes
- BZ - 538449 - ipsec-tools strict/MLS policy missing from RHEL 5.3 and RHEL 5.4 beta
- BZ - 538452 - Openswan FIPS-140 work blocked by AVCs
- BZ - 538453 - SELinux denies ssh-keygen from system_u:object_r:initrc_exec_t
- BZ - 538503 - MLS selinux-policy: setkey executed from initrc_t from if{up,down}-ipsec fails to set policies
CVEs
(none)
References
(none)
Red Hat Enterprise Linux Server 5
SRPM | |
---|---|
selinux-policy-2.4.6-255.el5_4.3.src.rpm | SHA-256: c6440d4ee2aad85951ff80606a2aa0ef459eda5c561a96d163dc068b26ee03a1 |
x86_64 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
ia64 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
i386 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 5.4
SRPM | |
---|---|
x86_64 | |
ia64 | |
i386 |
Red Hat Enterprise Linux Workstation 5
SRPM | |
---|---|
selinux-policy-2.4.6-255.el5_4.3.src.rpm | SHA-256: c6440d4ee2aad85951ff80606a2aa0ef459eda5c561a96d163dc068b26ee03a1 |
x86_64 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
i386 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
Red Hat Enterprise Linux Desktop 5
SRPM | |
---|---|
selinux-policy-2.4.6-255.el5_4.3.src.rpm | SHA-256: c6440d4ee2aad85951ff80606a2aa0ef459eda5c561a96d163dc068b26ee03a1 |
x86_64 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
i386 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
Red Hat Enterprise Linux for IBM z Systems 5
SRPM | |
---|---|
selinux-policy-2.4.6-255.el5_4.3.src.rpm | SHA-256: c6440d4ee2aad85951ff80606a2aa0ef459eda5c561a96d163dc068b26ee03a1 |
s390x | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 5.4
SRPM | |
---|---|
s390x |
Red Hat Enterprise Linux for Power, big endian 5
SRPM | |
---|---|
selinux-policy-2.4.6-255.el5_4.3.src.rpm | SHA-256: c6440d4ee2aad85951ff80606a2aa0ef459eda5c561a96d163dc068b26ee03a1 |
ppc | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
Red Hat Enterprise Linux for Power, big endian - Extended Update Support 5.4
SRPM | |
---|---|
ppc |
Red Hat Enterprise Linux Server from RHUI 5
SRPM | |
---|---|
selinux-policy-2.4.6-255.el5_4.3.src.rpm | SHA-256: c6440d4ee2aad85951ff80606a2aa0ef459eda5c561a96d163dc068b26ee03a1 |
x86_64 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
i386 | |
selinux-policy-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 4223b15270947cbb106de23eb5e7a3fe3504aba0ded261a59e05968004d57cca |
selinux-policy-devel-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 6a2715cd34a0d144257b9ff972171287ce0913f6f1bfc75708d57d6039e085af |
selinux-policy-minimum-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 51c595aec65a7a31f3e0159678ed5da2e94d6dd44d188cb6d73b314f8a220db7 |
selinux-policy-mls-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 9a066bfd08b2733cee817de22e72f1892277fe68c90b8ed757711ac55247ac18 |
selinux-policy-strict-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: 234e534aab99d77220c979bdf732b4009e604181b8509347028aa78e3f39249d |
selinux-policy-targeted-2.4.6-255.el5_4.3.noarch.rpm | SHA-256: fb39f1d02c01f13af7bdb64ee7bcdad19135e65c56ceb9db5715bdc228797c20 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.