Scientific Linux Security Update : selinux-policy enhancement update on SL6.x i386/x86_64 (20121112)

high Nessus Plugin ID 62918

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

This update adds the following enhancements :

- Previously, SELinux was blocking the /usr/libexec/qemu-kvm utility during a migration of a virtual machine from Red Hat Enterprise Virtualization Manager. Consequently, such a migration attempt failed and AVC messages were returned. This update fixes the virt_use_fusefs boolean and adds the sanlock_use_fusefs boolean, thus allowing the migration to succeed in the described scenario.

- When trying to start a virtual machine on a POSIX-compliant file system, SELinux denied the operation and returned AVC messages. This update amends the SELinux policy to allow the described scenario to succeed.

This update has been placed in the security tree to avoid selinux bugs.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?f25ffe5d

Plugin Details

Severity: High

ID: 62918

File Name: sl_20121112_selinux_policy_enhancement_update_on_SL6_x.nasl

Version: 1.5

Type: local

Agent: unix

Published: 11/14/2012

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:selinux-policy, p-cpe:/a:fermilab:scientific_linux:selinux-policy-doc, p-cpe:/a:fermilab:scientific_linux:selinux-policy-minimum, p-cpe:/a:fermilab:scientific_linux:selinux-policy-mls, p-cpe:/a:fermilab:scientific_linux:selinux-policy-targeted, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 11/12/2012

Vulnerability Publication Date: 11/12/2012