Bug ID 1178321
Summary AUDIT-0: udisks2: polkit-untracked-privilege
Classification openSUSE
Product openSUSE Tumbleweed
Version Current
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter milsav92@outlook.com
QA Contact security-team@suse.de
Found By ---
Blocker ---

libudisks2-0_lsm.x86_64: E: polkit-untracked-privilege (Badness: 10)
org.freedesktop.udisks2.lsm.manage-led (auth_admin:auth_admin:auth_admin_keep)
The privilege is not listed in /etc/polkit-default-privs.*         which makes
it harder for admins to find. Furthermore polkit         authorization checks
can easily introduce security issues. If the         package is intended for
inclusion in any SUSE product please open         a bug report to request
review of the package by the security team.         Please refer to
https://en.opensuse.org/openSUSE:Package_security_guidelines#audit_bugs for
more information.


It seems it was renamed from:
org.freedesktop.udisks2.manage-led
to:
org.freedesktop.udisks2.lsm.manage-led
in commit 6cef50624596e3f128698adb1402b389bad4792c

https://github.com/storaged-project/udisks/commit/6cef50624596e3f128698adb1402b389bad4792c#diff-dd9c6b44381920d6c381940478c9503ed164f828932d790865650fd6b40d32ae

which was released as part of usidsk2-2.9.0

PS. Is seems that when I branched Base:System/udisks2 I didn't pay attention to 
the fact that Base:System has:
Support: !rpmlint-Factory
set as a project configuration which propagated to the branched project.


You are receiving this mail because: