Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-15398

Confined sysadm cannot execute "sudo tcpdump" command [rhel-8]

    • selinux-policy-3.14.3-133.el8
    • Normal
    • sst_security_selinux
    • ssg_security
    • 20
    • QE ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Red Hat Enterprise Linux
    • Hide

      System administrator that is confined by SELinux (sysadm_u) can successfully run the tcpdump command via sudo. No SELinux denials are triggered during the run.

      Show
      System administrator that is confined by SELinux (sysadm_u) can successfully run the tcpdump command via sudo. No SELinux denials are triggered during the run.
    • Pass
    • Yes
    • Bug Fix
    • Hide
      .SELinux policy contains rules for additional services and applications

      This version of the `selinux-policy` package contains additional rules. Most notably, users in the `sysadm_r` role can execute the following commands:

      * `sudo traceroute`
      * `sudo tcpdump`
      * `sudo dnf`
      Show
      .SELinux policy contains rules for additional services and applications This version of the `selinux-policy` package contains additional rules. Most notably, users in the `sysadm_r` role can execute the following commands: * `sudo traceroute` * `sudo tcpdump` * `sudo dnf`
    • Done

      What were you trying to do that didn't work?

       Users mapped to sysadm_u cannot execute `sudo tcpdump` command because `tcpdump` executes in `sysadm_sudo_t` context due to missing rule to transition.

      Please provide the package NVR for which bug is seen:

      selinux-policy

      How reproducible:

      Always

      Steps to reproduce

      1. Execute `sudo tcpdump` from a confined user mapped to `sysadm_u`

      Expected results

      Works

      Actual results

      Fails

            rhn-support-zpytela Zdenek Pytela
            rhn-support-rmetrich Renaud Metrich
            Nikola Kňažeková Nikola Kňažeková (Inactive)
            Milos Malik Milos Malik
            Jan Fiala Jan Fiala
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

              Created:
              Updated:
              Resolved: