-
Thu Apr 02 2026 Darren Archibald <darren.archibald@oracle.com> - 42.1.18-4.0.1
- Allow systemd_fstab_generator_t to read udev pid files [Orabug: 37139639]
- Allow systemd_fstab_generator_t to read sysfs filesystem [Orabug: 37139639]
- Allow systemd_fstab_generator_t to get attributs of fixed_disk_device_t and
removable_device_t [Orabug: 37139639]
- Change reference in /etc/selinux/config to point to Oracle doc [Orabug: 36899915]
- Allow user_mail_domain to manage exim_log_t and exim_spool_t link files [Orabug: 36617121]
- Allow exim_t to read exim_log_t and manage exim_spool_t link files [Orabug: 36430005]
- Make import-state work with mls policy [Orabug: 32636699]
- Add map permission to lvm_t on lvm_metadata_t. [Orabug: 31405325]
- Add comment for map on lvm_metadata_t. [Orabug: 31405325]
- Make cloud-init work with mls policy [Orabug: 32430460]
- Allow systemd-pstore to transfer files from /sys/fs/pstore [Orabug: 31594666]
- Make lsmd and rngd work with mls policy [Orabug: 31405378]
- Allow virt_domain to mmap virt_content_t files [Orabug: 30932671]
- Add vhost-scsi to be vhost_device_t type [Orabug: 27774921]
- Allow ocfs2_dlmfs to be mounted with ocfs2_dlmfs_t type. [Orabug: 13333429]
-
Tue Mar 10 2026 Vit Mojzis <vmojzis@redhat.com> - 42.1.18.4
- Rebuild because of a missing target tag
Resolves: RHEL-152308
-
Fri Feb 27 2026 Vit Mojzis <vmojzis@redhat.com> - 42.1.18-2
- Rebuild for SELinux userspace 3.10
-
Mon Feb 23 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.18-1
- Allow NetworkManager list bpf directories
Resolves: RHEL-142171
- Dontaudit systemd-generator connect to sssd over a unix stream socket
Resolves: RHEL-114886
- Allow pkcsslotd read files in /proc and /sys
Resolves: RHEL-130812
- Allow pkcsslotd map its private tmpfs files
Resolves: RHEL-130812
- Allow tlshd communication to unconfined_t over a tcp socket
Resolves: RHEL-125106
- Label /run/insights-client.ppid with insights_client_run_t
Resolves: RHEL-146687
- Allow NM nvme dispatcher script start systemd services
Resolves: RHEL-140760
- Allow tlshd write generic certificate dirs
Resolves: RHEL-127023
- Allow aide get attributes of tmpfs and devtmpfs filesystems
Resolves: RHEL-121479
- Allow plasma login manager stop login services
Resolves: RHEL-140911
- Rebuild selinux policy after installation of the extra package
Resolves: RHEL-135875
Resolves: RHEL-143926
- Move triggerin scriptlets to the parent packages
Resolves: RHEL-141813
- Rebuild policy before running {binsbin|varrun}-convert.sh
Resolves: RHEL-141813
-
Wed Feb 18 2026 Veronika Syncakova <vsyncako@redhat.com> - 42.1.17-2
- Rebuild selinux policy after installation of the extra package
Resolves: RHEL-135875
-
Fri Feb 13 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.17-1
- Allow rhsmcertd read anaconda run files
Resolves: RHEL-141391
- Allow mdadm to use CAP_BPF during RAID monitoring
Resolves: RHEL-135765
- Allow mdadm the CAP_SYS_PTRACE capability
Resolves: RHEL-135765
- Allow staff and sysadm execute iotop using sudo
Resolves: RHEL-134940
- Allow kernel_t to read/write all domains' pipes
Resolves: RHEL-124442
- Allow nfsd_t domain setuid and setgid capability for rpc.mountd
Resolves: RHEL-148107
-
Fri Feb 06 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.16-1
- Allow sshd-session inherit limits from its parent sshd process
Resolves: RHEL-136673
- Revert "Allow sshd-session inherit limits from its parent process"
Resolves: RHEL-136673
- Allow tlshd write generic certificates
Resolves: RHEL-123737
- Allow systemd-hostnamed to create its Varlink socket
Resolves: RHEL-139385
- Update gpg_role() interface with unix_stream_socket permissions
Resolves: RHEL-128555
- Label /etc/aliases.cdb with etc_aliases_t
Resolves: RHEL-109976
- Add aliases.lmdb to mta_filetrans_named_content()
Resolves: RHEL-140884
- Update policy for bootupd
Resolves: RHEL-141391
-
Tue Jan 27 2026 Vit Mojzis <vmojzis@redhat.com> - 42.1.15-2
- Macros: Require only "stable" version of selinux-policy (RHEL-141423)
-
Mon Jan 26 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.15-1
- Allow hostapd write to socket files in /tmp
Resolves: RHEL-77047
- Allow stap server read virtual memory sysctls
Resolves: RHEL-114104
- Allow sshd-session inherit limits from its parent process
Resolves: RHEL-136673
- Allow sshd noatsecure on sshd-session execution
Resolves: RHEL-138247
- Allow sshd-net read and write to sshd vsock socket
Related: RHEL-138247
-
Fri Jan 09 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.14-1
- Update ktls policy
Resolves: RHEL-123737
- Update policy for redfish-finder
Resolves: RHEL-50299
- Allow sshd-session read, write, and map ica tmpfs files
Resolves: RHEL-138247
- Allow sshd_net_t ioctl on unix_stream_socket of sshd_session_t
Resolves: RHEL-127721
- Allow stalld map sysfs files
Resolves: RHEL-135512
- Allow aide get attributes of a filesystem with extended attributes
Resolves: RHEL-121479
- Label miscellaneous /dev/papr-* devices
Resolves: RHEL-129839
- Allow KDE Plasma Login Manager to function as a display manager
Resolves: RHEL-135676
- Update specfile trigger for openwsmand
Resolves: RHEL-133024