Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 16th February 2009, 09:13 AM
Thaidog Offline
Registered User
 
Join Date: Feb 2006
Posts: 184
Exclamation SE Linux denial iptables-restor

I'm getting the following denial when I start up sshd or restart iptables... etc:

Code:
Summary:

SELinux is preventing iptables-restor (iptables_t) "read write" unconfined_t.

Detailed Description:

SELinux denied access requested by iptables-restor. It is not expected that this
access is required by iptables-restor and this access may signal an intrusion
attempt. It is also possible that the specific version or configuration of the
application is causing it to require additional access.

Allowing Access:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Or you can disable
SELinux protection altogether. Disabling SELinux protection is not recommended.
Please file a bug report (http://bugzilla.redhat.com/bugzilla/enter_bug.cgi)
against this package.

Additional Information:

Source Context                unconfined_u:system_r:iptables_t:s0
Target Context                unconfined_u:unconfined_r:unconfined_t:s0
Target Objects                socket [ unix_stream_socket ]
Source                        iptables
Source Path                   /sbin/iptables
Port                          <Unknown>
Host                          iccproject.localdomain
Source RPM Packages           iptables-1.4.1.1-2.fc10
Target RPM Packages           
Policy RPM                    selinux-policy-3.5.13-44.fc10
Selinux Enabled               True
Policy Type                   targeted
MLS Enabled                   True
Enforcing Mode                Enforcing
Plugin Name                   catchall
Host Name                     iccproject.localdomain
Platform                      Linux iccproject.localdomain
                              2.6.27.12-170.2.5.fc10.i686 #1 SMP Wed Jan 21
                              02:09:37 EST 2009 i686 i686
Alert Count                   7
First Seen                    Sun 15 Feb 2009 01:42:47 AM EST
Last Seen                     Sun 15 Feb 2009 01:42:47 AM EST
Local ID                      a2585788-bf8a-419d-8692-4a2996e648b3
Line Numbers                  

Raw Audit Messages            

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10208]" dev=sockfs ino=10208 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=AVC msg=audit(1234680167.209:564): avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket

node=iccproject.localdomain type=SYSCALL msg=audit(1234680167.209:564): arch=40000003 syscall=11 success=yes exit=0 a0=8ca8a68 a1=8ca9140 a2=8c82330 a3=0 items=2 ppid=12082 pid=12122 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=1 comm="iptables-restor" exe="/sbin/iptables-restore" subj=unconfined_u:system_r:iptables_t:s0 key=(null)

node=iccproject.localdomain type=CWD msg=audit(1234680167.209:564): cwd="/"

node=iccproject.localdomain type=PATH msg=audit(1234680167.209:564): item=0 name="/sbin/iptables-restore" inode=3810 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:iptables_exec_t:s0

node=iccproject.localdomain type=PATH msg=audit(1234680167.209:564): item=1 name=(null) inode=82094 dev=fd:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0
Reply With Quote
  #2  
Old 16th February 2009, 05:40 PM
domg472 Offline
SELinux Contributor
 
Join Date: May 2008
Posts: 621
I am not sure but my guess is that this is caused by a leaked file descriptor (bug). In any case please consider reporting this issue to bugzilla.redhat.com in the selinux-policy component.

To allow this access:

Code:
echo "avc:  denied  { read write } for  pid=12122 comm="iptables-restor" path="socket:[10050]" dev=sockfs ino=10050 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket" | audit2allow -M myiptables; sudo /usr/sbin/semodule -i myiptables.pp
__________________
Come join us on #fedora-selinux on irc.freenode.org
http://docs.fedoraproject.org/selinu...ide/f10/en-US/
Reply With Quote
Reply

Tags
denial, iptablesrestor, linux

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
SE Linux denial when trying to launch Google earth Thaidog Security and Privacy 2 27th January 2009 08:15 AM
PHP mail() Linux SE Denial keatonvictor Using Fedora 3 1st March 2008 08:40 PM
iptables-restor avc error drewsmith Servers & Networking 0 8th November 2007 11:22 AM
ftp behind linux fc4 (iptables) ammad Servers & Networking 0 20th December 2005 02:34 PM


Current GMT-time: 02:06 (Saturday, 25-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat