ELBA-2026-3475

ELBA-2026-3475 - selinux-policy bug fix and enhancement update

Type:BUG
Impact:NA
Release Date:2026-03-05

Description


[42.1.7-1.0.2.el10_1.1]
- Fix specfile triggers for fapolicyd and usbguard DSP modules [Orabug: 38681740] [Orabug: 38579739]
- Allow systemd_fstab_generator_t to read udev pid files [Orabug: 37139639]
- Allow systemd_fstab_generator_t to read sysfs filesystem [Orabug: 37139639]
- Allow systemd_fstab_generator_t to get attributs of fixed_disk_device_t and
removable_device_t [Orabug: 37139639]
- Change reference in /etc/selinux/config to point to Oracle doc [Orabug: 36899915]
- Allow user_mail_domain to manage exim_log_t and exim_spool_t link files [Orabug: 36617121]
- Allow exim_t to read exim_log_t and manage exim_spool_t link files [Orabug: 36430005]
- Make import-state work with mls policy [Orabug: 32636699]
- Add map permission to lvm_t on lvm_metadata_t. [Orabug: 31405325]
- Add comment for map on lvm_metadata_t. [Orabug: 31405325]
- Make cloud-init work with mls policy [Orabug: 32430460]
- Allow systemd-pstore to transfer files from /sys/fs/pstore [Orabug: 31594666]
- Make lsmd and rngd work with mls policy [Orabug: 31405378]
- Allow virt_domain to mmap virt_content_t files [Orabug: 30932671]
- Add vhost-scsi to be vhost_device_t type [Orabug: 27774921]
- Allow ocfs2_dlmfs to be mounted with ocfs2_dlmfs_t type. [Orabug: 13333429]

[42.1.7-1.1]
- Allow nfsd_t domain setuid and setgid capability for rpc.mountd
Resolves: RHEL-148248




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_aarch64_appstream
selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_aarch64_baseos_latest
selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_aarch64_codeready_builder
selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_aarch64_u1_baseos_patch
selinux-policy-42.1.7-1.0.2.el10_1.1.noarch.rpmec140a1c5c93632f419d17ba6b686dc3b3c4133c1b1bea2fa832b7ff19ee867d-ol10_aarch64_baseos_latest
selinux-policy-42.1.7-1.0.2.el10_1.1.noarch.rpmec140a1c5c93632f419d17ba6b686dc3b3c4133c1b1bea2fa832b7ff19ee867d-ol10_aarch64_u1_baseos_patch
selinux-policy-devel-42.1.7-1.0.2.el10_1.1.noarch.rpm6b6b57f55f500ec871174cd25ff1621ccd6639c965ba64037a99faa0b45b3ffb-ol10_aarch64_appstream
selinux-policy-doc-42.1.7-1.0.2.el10_1.1.noarch.rpma004b28f9f5a51bf6d02620de1968ec923c5ea6515a643619d444342c06c2537-ol10_aarch64_baseos_latest
selinux-policy-doc-42.1.7-1.0.2.el10_1.1.noarch.rpma004b28f9f5a51bf6d02620de1968ec923c5ea6515a643619d444342c06c2537-ol10_aarch64_u1_baseos_patch
selinux-policy-extra-42.1.7-1.0.2.el10_1.1.noarch.rpm9779c05c7e5962a4a0f1e09d5af3579533a78dfc982ea65b3020f8b39c70c6e1-ol10_aarch64_codeready_builder
selinux-policy-mls-42.1.7-1.0.2.el10_1.1.noarch.rpmfa62882dee73b3d4137a5671004001ba91f06e7511a8e4905a57ba1e9d44562b-ol10_aarch64_baseos_latest
selinux-policy-mls-42.1.7-1.0.2.el10_1.1.noarch.rpmfa62882dee73b3d4137a5671004001ba91f06e7511a8e4905a57ba1e9d44562b-ol10_aarch64_u1_baseos_patch
selinux-policy-mls-extra-42.1.7-1.0.2.el10_1.1.noarch.rpme137f7a81b4570474c84805af6968c3ae310499f935ef4584c5d22bb4b1c91b1-ol10_aarch64_codeready_builder
selinux-policy-sandbox-42.1.7-1.0.2.el10_1.1.noarch.rpm5b31fc17e52d6ccf6d8cbeaf2b4e1ec047d1e17a482e85e0c00ca84b21c5d685-ol10_aarch64_baseos_latest
selinux-policy-sandbox-42.1.7-1.0.2.el10_1.1.noarch.rpm5b31fc17e52d6ccf6d8cbeaf2b4e1ec047d1e17a482e85e0c00ca84b21c5d685-ol10_aarch64_u1_baseos_patch
selinux-policy-targeted-42.1.7-1.0.2.el10_1.1.noarch.rpm59f965235988fc7f2b74e0be441b4ac416e1b1b08594b5a5720392ffcc498df7-ol10_aarch64_baseos_latest
selinux-policy-targeted-42.1.7-1.0.2.el10_1.1.noarch.rpm59f965235988fc7f2b74e0be441b4ac416e1b1b08594b5a5720392ffcc498df7-ol10_aarch64_u1_baseos_patch
selinux-policy-targeted-extra-42.1.7-1.0.2.el10_1.1.noarch.rpme2f411cdb09ee380b3a28a3f864037f9c89d29cef6093610df0c19108b476ff9-ol10_aarch64_codeready_builder
Oracle Linux 10 (x86_64) selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_x86_64_appstream
selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_x86_64_baseos_latest
selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_x86_64_codeready_builder
selinux-policy-42.1.7-1.0.2.el10_1.1.src.rpm3cfa22edc67d610037f3c4126d64f9933c63704a1daf67da80b0355486c0d09d-ol10_x86_64_u1_baseos_patch
selinux-policy-42.1.7-1.0.2.el10_1.1.noarch.rpmec140a1c5c93632f419d17ba6b686dc3b3c4133c1b1bea2fa832b7ff19ee867d-ol10_x86_64_baseos_latest
selinux-policy-42.1.7-1.0.2.el10_1.1.noarch.rpmec140a1c5c93632f419d17ba6b686dc3b3c4133c1b1bea2fa832b7ff19ee867d-ol10_x86_64_u1_baseos_patch
selinux-policy-devel-42.1.7-1.0.2.el10_1.1.noarch.rpm6b6b57f55f500ec871174cd25ff1621ccd6639c965ba64037a99faa0b45b3ffb-ol10_x86_64_appstream
selinux-policy-doc-42.1.7-1.0.2.el10_1.1.noarch.rpma004b28f9f5a51bf6d02620de1968ec923c5ea6515a643619d444342c06c2537-ol10_x86_64_baseos_latest
selinux-policy-doc-42.1.7-1.0.2.el10_1.1.noarch.rpma004b28f9f5a51bf6d02620de1968ec923c5ea6515a643619d444342c06c2537-ol10_x86_64_u1_baseos_patch
selinux-policy-extra-42.1.7-1.0.2.el10_1.1.noarch.rpm9779c05c7e5962a4a0f1e09d5af3579533a78dfc982ea65b3020f8b39c70c6e1-ol10_x86_64_codeready_builder
selinux-policy-mls-42.1.7-1.0.2.el10_1.1.noarch.rpmfa62882dee73b3d4137a5671004001ba91f06e7511a8e4905a57ba1e9d44562b-ol10_x86_64_baseos_latest
selinux-policy-mls-42.1.7-1.0.2.el10_1.1.noarch.rpmfa62882dee73b3d4137a5671004001ba91f06e7511a8e4905a57ba1e9d44562b-ol10_x86_64_u1_baseos_patch
selinux-policy-mls-extra-42.1.7-1.0.2.el10_1.1.noarch.rpme137f7a81b4570474c84805af6968c3ae310499f935ef4584c5d22bb4b1c91b1-ol10_x86_64_codeready_builder
selinux-policy-sandbox-42.1.7-1.0.2.el10_1.1.noarch.rpm5b31fc17e52d6ccf6d8cbeaf2b4e1ec047d1e17a482e85e0c00ca84b21c5d685-ol10_x86_64_baseos_latest
selinux-policy-sandbox-42.1.7-1.0.2.el10_1.1.noarch.rpm5b31fc17e52d6ccf6d8cbeaf2b4e1ec047d1e17a482e85e0c00ca84b21c5d685-ol10_x86_64_u1_baseos_patch
selinux-policy-targeted-42.1.7-1.0.2.el10_1.1.noarch.rpm59f965235988fc7f2b74e0be441b4ac416e1b1b08594b5a5720392ffcc498df7-ol10_x86_64_baseos_latest
selinux-policy-targeted-42.1.7-1.0.2.el10_1.1.noarch.rpm59f965235988fc7f2b74e0be441b4ac416e1b1b08594b5a5720392ffcc498df7-ol10_x86_64_u1_baseos_patch
selinux-policy-targeted-extra-42.1.7-1.0.2.el10_1.1.noarch.rpme2f411cdb09ee380b3a28a3f864037f9c89d29cef6093610df0c19108b476ff9-ol10_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete