Hi All, Last month, I wrote about Xorg X server vulnerability and we have a new interesting vulnerability, now in PolicyKit. The exploit is based
Author: lvrabec
CVE-2018-14665 : Xorg X Server Vulnerabilities vs. SELinux
Hi All! There is a new interesting CVE. An incorrect permission check for -modulepath and -logfile options when starting Xorg X server allows unprivileged users
How get file name from inode number?
Hi All, I will generate SELinux denial using following command: # cd /root ; passwd –help >& output.txt # ausearch -m AVC -ts recent type=AVC
How to enable full auditing in audit daemon?
Full auditing in audit deamon could be useful e.g. to identify which object on system has too tight rules and object is causing dac_override SELinux
Why do you see DAC_OVERRIDE SELinux denials?
Hello everyone! You could have seen SELinux denials (AVC messages) in your system in the recent release of Fedora 28 and of course Fedora Rawhide.
Newest SELinux policy every day!
SELinux policy for Fedora Rawhide and Fedora 27 is changing very dynamically and new rules are appearing in SELinux policy repositories almost every day. New
No more massive patches in selinux-policy rpm package
Hi SELinux folks, Building selinux-policy rpm package was quite complicated and confusing for developers because of massive patches against Tresys reference base and contrib repositories.
Using rpm macros in product SELinux subpackages
Some time ago, I published a post about shipping custom SELinux modules together with product as rpm subpackage. One of the steps in shipping custom
Shipping custom module using SELinux priorities
Hello everyone! Some time ago I introduced first part of shipping own custom module with rpm package of your application. This solution allows you to
Creating local module quickly in CIL!
Welcome! Today, I’ll show you how to create local policy module for testing purposes or workaround while issue will be fixed in our distro selinux-policy.