linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* audit-3.0.6 released
@ 2021-10-01 17:21 Steve Grubb
  0 siblings, 0 replies; only message in thread
From: Steve Grubb @ 2021-10-01 17:21 UTC (permalink / raw)
  To: Linux Audit

Hello,

I've just released a new version of the audit daemon. It can be
downloaded from http://people.redhat.com/sgrubb/audit. It will also be
in rawhide soon. The ChangeLog is:

- Fixed various issues when dealing with corrupted logs
- Make IPX packet interpretation dependent on the ipx header file existing
- Add b32/b64 support to ausyscall (Egor Ignatov)
- Add support for armv8l (Egor Ignatov)
- Fix auditctl list of syscalls in PPC (Egor Ignatov)
- auditd.service now restarts auditd under some conditions (Timothée Ravier)

The main driver for this release is that there are a scattering of bug 
reports of segfaults on the previous release. The auparse library has been 
documented for years to fabricate 2 non-existing fields, seresult and seperm. 
Somehow, seresult was added to SELINUX_ERR over the years and this was not 
noticed. So, when auparse is done with an event and is cleaning up, it thinks 
it owns the seresult field and frees it. On the SELINUX_ERR record, it's a 
real field that can't be freed and that leads to the segfault. The code doing 
cleanup was refactored to not make the decision based on the field's name. The 
resulting code should be slightly faster.

SHA256: c3e44d77513a42401d417dd0ceb203cf23886cb89402dea7b9494faa3f4fcc5e

Please let me know if you run across any problems with this release.

-Steve



--
Linux-audit mailing list
Linux-audit@redhat.com
https://listman.redhat.com/mailman/listinfo/linux-audit


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2021-10-01 17:21 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-10-01 17:21 audit-3.0.6 released Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).