Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-15432

Confined sysadm cannot execute "sudo tcpdump" command [rhel-9]

    • selinux-policy-38.1.30-1.el9
    • Normal
    • sst_security_selinux
    • ssg_security
    • 20
    • QE ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Red Hat Enterprise Linux
    • Hide

      System administrator that is confined by SELinux (sysadm_u) can successfully run the tcpdump command via sudo. No SELinux denials are triggered during the run.

      Show
      System administrator that is confined by SELinux (sysadm_u) can successfully run the tcpdump command via sudo. No SELinux denials are triggered during the run.
    • Pass
    • Yes
    • Bug Fix
    • Hide
      .SELinux policy contains rules for additional services and applications

      This version of the `selinux-policy` package contains additional rules. Most notably, users in the `sysadm_r` role can execute the following commands:

      * `sudo traceroute` (RHEL-14077)
      * `sudo tcpdump` (RHEL-15432)
      Show
      .SELinux policy contains rules for additional services and applications This version of the `selinux-policy` package contains additional rules. Most notably, users in the `sysadm_r` role can execute the following commands: * `sudo traceroute` ( RHEL-14077 ) * `sudo tcpdump` ( RHEL-15432 )
    • Done

      What were you trying to do that didn't work?

       Users mapped to sysadm_u cannot execute `sudo tcpdump` command because `tcpdump` executes in `sysadm_sudo_t` context due to missing rule to transition.

      Please provide the package NVR for which bug is seen:

      selinux-policy

      How reproducible:

      Always

      Steps to reproduce

      1. Execute `sudo tcpdump` from a confined user mapped to `sysadm_u`

      Expected results

      Works

      Actual results

      Fails

            rhn-support-zpytela Zdenek Pytela
            rhn-support-rmetrich Renaud Metrich
            Zdenek Pytela
            Nikola Kňažeková Nikola Kňažeková (Inactive)
            Milos Malik Milos Malik
            Jan Fiala Jan Fiala
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: