- Issued:
- 2020-11-30
- Updated:
- 2020-11-30
RHBA-2020:5241 - Bug Fix Advisory
Synopsis
fapolicyd bug fix update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for fapolicyd is now available for Red Hat Enterprise Linux 8.1 Extended Update Support.
Description
The fapolicyd software framework introduces a form of application whitelisting
and blacklisting based on a user-defined policy. The application whitelisting
feature provides one of the most efficient ways to prevent running untrusted and possibly malicious applications on the system.
Bug Fix:
- When an update replaces the binary of a running application, the kernel modifies the application binary path in memory by appending the " (deleted)" suffix. Previously, the fapolicyd file access policy daemon treated such applications as untrusted, and prevented them from opening and executing any other files. As a consequence, the system was sometimes unable to boot after applying updates.
With this update, fapolicyd ignores the suffix in the binary path so the binary can match the trust database. As a result, fapolicyd enforces the rules correctly and the update process can finish.
(BZ#1897092)
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.1 x86_64
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.1 s390x
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.1 ppc64le
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.1 aarch64
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64
Fixes
- BZ - 1897092 - fapolicyd breaks system upgrade, leaving system in dead state - complete fix [rhel-8.1.0.z]
CVEs
(none)
References
(none)
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.1
SRPM | |
---|---|
fapolicyd-0.8.10-3.el8_1.6.src.rpm | SHA-256: 00f35ecbb047a2da5f427d3dec992df7df7949e89ca5b7ff602fd078aa13af3b |
x86_64 | |
fapolicyd-0.8.10-3.el8_1.6.x86_64.rpm | SHA-256: ae2493cacc44c232ec224921f0147cb14c785f73aee2098ad2f5cf0c3372f9e8 |
fapolicyd-debuginfo-0.8.10-3.el8_1.6.x86_64.rpm | SHA-256: a4e14c453acca8bf2649c1031f1858aee1e721532ba1496aa35f52cbe07f5e3e |
fapolicyd-debugsource-0.8.10-3.el8_1.6.x86_64.rpm | SHA-256: 48e9bde2f133891c499ce59de31f1c04e5b83b8e894be94cb7e4d6733b5f047a |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.1
SRPM | |
---|---|
fapolicyd-0.8.10-3.el8_1.6.src.rpm | SHA-256: 00f35ecbb047a2da5f427d3dec992df7df7949e89ca5b7ff602fd078aa13af3b |
s390x | |
fapolicyd-0.8.10-3.el8_1.6.s390x.rpm | SHA-256: a11195303a77744b879a192dc8d8adebaebac7ac4b898a97aa9d64edd8bb17f3 |
fapolicyd-debuginfo-0.8.10-3.el8_1.6.s390x.rpm | SHA-256: e30558df9ae96273e8cfa7a0d5b4e61168379f62d8b67b34e7e3465354ad344f |
fapolicyd-debugsource-0.8.10-3.el8_1.6.s390x.rpm | SHA-256: f0aef0ad50b437b1959768f574f9c05118ac14f9be333af13f38df4886cd3029 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.1
SRPM | |
---|---|
fapolicyd-0.8.10-3.el8_1.6.src.rpm | SHA-256: 00f35ecbb047a2da5f427d3dec992df7df7949e89ca5b7ff602fd078aa13af3b |
ppc64le | |
fapolicyd-0.8.10-3.el8_1.6.ppc64le.rpm | SHA-256: 9d63cc42de217db1b4fdeedf7c9518a9f00311843a6eb30bf63eb14769b80928 |
fapolicyd-debuginfo-0.8.10-3.el8_1.6.ppc64le.rpm | SHA-256: 3568664f24cdce06db6318c7012bad86f4d6e8be5a935ab8fa0aeb2728c9a177 |
fapolicyd-debugsource-0.8.10-3.el8_1.6.ppc64le.rpm | SHA-256: ed48ea1d8e6d30840e6ec49604175eadb8e385c5377df0b283011f530683170f |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.1
SRPM | |
---|---|
fapolicyd-0.8.10-3.el8_1.6.src.rpm | SHA-256: 00f35ecbb047a2da5f427d3dec992df7df7949e89ca5b7ff602fd078aa13af3b |
aarch64 | |
fapolicyd-0.8.10-3.el8_1.6.aarch64.rpm | SHA-256: 658b48fc324af6e8c3190b2065b31237f8f3d6211f578f47631c650e7dc1d2c4 |
fapolicyd-debuginfo-0.8.10-3.el8_1.6.aarch64.rpm | SHA-256: c32c5681470e0fa122f375eb8b723d42a78438797b830e269ca6d8a3b3663dde |
fapolicyd-debugsource-0.8.10-3.el8_1.6.aarch64.rpm | SHA-256: 47ea067ceae727368bc61a62f0f9d9fb5f0195bc307c7a9e88dc153cb6a9eaf4 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1
SRPM | |
---|---|
fapolicyd-0.8.10-3.el8_1.6.src.rpm | SHA-256: 00f35ecbb047a2da5f427d3dec992df7df7949e89ca5b7ff602fd078aa13af3b |
ppc64le | |
fapolicyd-0.8.10-3.el8_1.6.ppc64le.rpm | SHA-256: 9d63cc42de217db1b4fdeedf7c9518a9f00311843a6eb30bf63eb14769b80928 |
fapolicyd-debuginfo-0.8.10-3.el8_1.6.ppc64le.rpm | SHA-256: 3568664f24cdce06db6318c7012bad86f4d6e8be5a935ab8fa0aeb2728c9a177 |
fapolicyd-debugsource-0.8.10-3.el8_1.6.ppc64le.rpm | SHA-256: ed48ea1d8e6d30840e6ec49604175eadb8e385c5377df0b283011f530683170f |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1
SRPM | |
---|---|
fapolicyd-0.8.10-3.el8_1.6.src.rpm | SHA-256: 00f35ecbb047a2da5f427d3dec992df7df7949e89ca5b7ff602fd078aa13af3b |
x86_64 | |
fapolicyd-0.8.10-3.el8_1.6.x86_64.rpm | SHA-256: ae2493cacc44c232ec224921f0147cb14c785f73aee2098ad2f5cf0c3372f9e8 |
fapolicyd-debuginfo-0.8.10-3.el8_1.6.x86_64.rpm | SHA-256: a4e14c453acca8bf2649c1031f1858aee1e721532ba1496aa35f52cbe07f5e3e |
fapolicyd-debugsource-0.8.10-3.el8_1.6.x86_64.rpm | SHA-256: 48e9bde2f133891c499ce59de31f1c04e5b83b8e894be94cb7e4d6733b5f047a |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.