📖 ~4 min read • Source: AlmaLinux ALSA ALSA-2020:4451
Related CVEs: CVE-2019-8625 CVE-2019-8710 CVE-2019-8720 CVE-2019-8743 CVE-2019-8764 CVE-2019-8766 CVE-2019-8769 CVE-2019-8771 +12 more
Upstream summary: GNOME is the default desktop environment of AlmaLinux.
The following packages have been upgraded to a later upstream version: gnome-remote-desktop (0.1.8), pipewire (0.3.6), vte291 (0.52.4), webkit2gtk3 (2.28.4), xdg-desktop-portal (1.6.0), xdg-desktop-portal-gtk (1.6.0). (BZ#1775345, BZ#1779691, BZ#1817143, BZ#1832347, BZ#1837406)
Security Fix(es):
* webkitgtk: Multiple security issues (CVE-2019-8625, CVE-2019-8710, CVE-2019-8720, CVE-2019-8743, CVE-2019-8764, CVE-2019-87
Table of contents
Symptom & Impact
On AlmaLinux 8 hosts running tracker, the vulnerable code is started by something else – a web or application server, or an on-demand supervisor such as inetd, xinetd or a systemd socket unit – rather than by a service of its own. Patching replaces the files on disk immediately, but a long-running parent that has already loaded them (PHP-FPM workers, an application server, a persistent worker pool) keeps serving the old code until it is recycled. Connection-per-process supervisors pick the fix up on the next connection, so the exposure window differs sharply between the two and is worth confirming rather than assuming. tracker is started by a hosting server or an on-demand supervisor rather than by a unit of its own, so restart whatever launches it – not tracker.
Environment & Reproduction
Reproduction targets AlmaLinux 8. Confirm release and the installed package:
cat /etc/almalinux-release
cat /etc/os-release
rpm -q tracker
dnf info tracker | head -20
Exercise the workload that uses tracker while collecting:
sudo needs-restarting -u # --useronly: restrict to the invoking user's processes (useful on shared/app hosts)
sudo lsof -n +L1 # link count < 1 = file deleted but still open/mmap'd; this is the ground truth after an RPM replaces a .so (package: lsof)
sudo lsof -n +L1 2>/dev/null | awk 'NR>1 {print $1, $2}' | sort -u # condensed COMMAND + PID list of every process still running old code
sudo journalctl -xe --no-pager | tail -200
sudo tail -200 /var/log/dnf.log
sudo tail -200 /var/log/audit/audit.log
# For an evidence bundle bundle with sosreport:
sudo sosreport --batch
Root Cause Analysis
Root cause is documented in AlmaLinux ALSA ALSA-2020:4451. AlmaLinux / Red Hat maintainers shipped fixes in the corresponding tracker update for AlmaLinux 8; running an outdated build leaves the host exposed to the failure modes described in the advisory. Correlate dnf history with system logs:
sudo dnf history | head
sudo dnf history list tracker
sudo dnf history info <id>
sudo ausearch -m AVC,USER_AVC -ts today | tail -100
cat /proc/sys/kernel/tainted # non-zero = tainted kernel / out-of-tree modules
Quick Triage
Run these on AlmaLinux 8 to capture the current state of tracker:
rpm -q tracker # installed NVR
rpm -V tracker # verify shipped files
sudo dnf check-update --security
sudo dnf updateinfo list cves
systemctl --failed --no-pager
sudo firewall-cmd --list-all
getenforce && sestatus
dnf repoquery -l tracker 2>/dev/null | grep -E '/lib/systemd/system/.*\.(service|socket|timer)$' # same check WITHOUT installing (EL7/Amazon Linux 2: yum install yum-utils, then: repoquery -l tracker)
systemctl show --no-pager -p Type,RemainAfterExit <UNIT> # Type=oneshot (often paired with a .timer) means a one-shot job, NOT a daemon -- do not 'restart' it, let the timer fire
Step-by-Step Diagnosis
-
List failed systemd units.
systemctl --failed --no-pager -
Tail the journal for
trackerand the system bus.sudo journalctl -xe -f --no-pager -
Inspect firewall posture.
sudo firewall-cmd --list-all-zones --permanent sudo nft list ruleset 2>/dev/null | head -50 -
Surface SELinux denials and author a local policy module if needed.
sudo ausearch -m AVC,USER_AVC -ts today sudo ausearch -m AVC -ts today | audit2allow -a -M /tmp/local-fix sudo semodule -i /tmp/local-fix.pp -
Verify
trackerintegrity and reinstall if anything is altered.sudo rpm -V tracker sudo dnf reinstall tracker -
Correlate findings with
/var/log/dnf.log,dnf history, and AlmaLinux ALSA ALSA-2020:4451 to pin the change that introduced the regression.
Solution – Primary Fix
Apply the corrective dnf transaction referenced by AlmaLinux ALSA ALSA-2020:4451, then reload affected systemd units:
sudo dnf -y makecache
sudo dnf -y upgrade --security # apply ALL security errata (recommended)
# Or target a single package:
sudo dnf -y upgrade tracker
sudo systemctl daemon-reload
# Unit name may differ from pkg name; check first:
sudo needs-restarting -s | sort -u # STEP 1: read the list before acting. dbus.service, systemd-logind.service and PID 1 must NOT be blind-restarted on a live host -- those mean 'reboot'
sudo systemctl daemon-reload # STEP 3: pick up any unit files the update rewrote
sudo systemctl restart <UNIT> && sudo systemctl is-active <UNIT> && sudo systemctl status --no-pager --full <UNIT> # single-unit path, with an immediate health check
systemctl --user list-units --type=service --no-pager # desktop/session and per-user services are a separate manager; restart them with: systemctl --user restart <UNIT>
rpm -q tracker # confirm new NVR
For kernel / glibc / systemd / openssl advisories a reboot is required (or kpatch where licensed):
sudo needs-restarting -r # report whether reboot needed
sudo systemctl reboot # or: sudo shutdown -r now
# kpatch (Red Hat / Oracle) avoids reboot for many kernel CVEs:
sudo dnf install -y kpatch kpatch-dnf
sudo dnf kpatch auto # enable auto-patching
sudo kpatch list
Need help rolling this patch across an AlmaLinux fleet? Our IT Solutions & Services team manages AlmaLinux / RHEL patch windows with Pulp / Foreman / Spacewalk plus kpatch. Get in touch for a free consultation.
Solution – Alternative Approaches
If the primary patch is not viable, choose from these:
-
Roll back the offending dnf transaction:
sudo dnf history list | head sudo dnf history info <id> sudo dnf history undo <id> -
Version-lock the package so dnf cannot upgrade it:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add tracker sudo dnf versionlock list sudo dnf versionlock delete tracker # remove the lock -
Install an older NVR if a regression is suspected:
dnf --showduplicates list tracker | tac | head sudo dnf install -y --allowerasing tracker-<older-NVR> -
Switch SELinux to permissive briefly to confirm policy is the cause, then re-enforce:
sudo setenforce 0 # reproduce, capture denials, author a custom module: sudo ausearch -m AVC -ts recent | audit2allow -a -M mylocal sudo semodule -i mylocal.pp sudo setenforce 1 -
Take an LVM snapshot before kernel / glibc upgrades for fast rollback:
sudo lvs sudo lvcreate -s -n preupgrade -L 4G /dev/<vg>/<lv> # revert later via: sudo lvconvert --merge /dev/<vg>/preupgrade && sudo systemctl reboot -
Where kpatch is licensed, apply kernel fixes without reboot:
sudo kpatch list sudo kpatch load /usr/lib/modules/$(uname -r)/extra/kpatch/*.ko
Verification & Acceptance Criteria
All of these should pass after the fix:
rpm -q tracker # expected fixed NVR
sudo dnf updateinfo list cves --installed # CVEs above no longer listed
sudo firewall-cmd --list-services
getenforce
sudo needs-restarting -r
The conditions described in the advisory must no longer be reported for tracker across two consecutive runs.
Rollback Plan
Capture state before any change:
rpm -qa > /root/rpm-pre.txt
sudo dnf history list > /root/dnf-history-pre.txt
# Optional LVM snapshot of the root LV:
sudo lvcreate -s -n preupgrade -L 4G /dev/<vg>/<lv>
To revert if the patch is bad:
sudo dnf history undo <id>
# Or downgrade just the package:
sudo dnf install -y --allowerasing tracker-<older-NVR>
sudo systemctl daemon-reload
# Or merge the LVM snapshot and reboot:
sudo lvconvert --merge /dev/<vg>/preupgrade && sudo systemctl reboot
# Custom SELinux policy cleanup:
sudo semodule -r mylocal
Prevention & Hardening
Reduce the chance of this recurring on AlmaLinux 8:
-
Enable automatic security patching:
sudo dnf install -y dnf-automatic sudo sed -i 's/^upgrade_type.*/upgrade_type = security/' /etc/dnf/automatic.conf sudo sed -i 's/^apply_updates.*/apply_updates = yes/' /etc/dnf/automatic.conf sudo systemctl enable --now dnf-automatic.timer -
Subscribe to almalinux-announce and watch Red Hat security updates for upstream changes.
-
Mirror through a local Pulp / Foreman / Spacewalk-style repo for controlled rollouts:
sudo dnf install -y dnf-utils createrepo_c sudo reposync --download-metadata --downloadcomps -p /srv/mirror -- repoid=baseos sudo createrepo_c /srv/mirror/baseos -
Version-lock sensitive packages so they cannot be auto-upgraded:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add tracker -
Monitor file integrity with AIDE:
sudo dnf install -y aide sudo aide --init && sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz sudo aide --check -
Enable kpatch so kernel CVEs can be remediated without reboot:
sudo dnf install -y kpatch kpatch-dnf sudo dnf kpatch auto sudo kpatch list -
Keep SELinux in enforcing mode and review custom modules in
/etc/selinux/targeted/after every package upgrade. -
Apply CIS AlmaLinux 8 Benchmark hardening and remove unused packages.
Related Errors & Cross-Refs
Issues that commonly surface alongside a tracker update: dnf lock contention, systemd unit ordering cycles, SELinux AVC bursts, firewalld zone drift, and kernel taint flags. Useful triage:
sudo dnf check
systemd-analyze critical-chain
sudo ausearch -m AVC -ts today | tail
sudo firewall-cmd --get-active-zones
cat /proc/sys/kernel/tainted
sudo needs-restarting -r
View all almalinux-8 tutorials on the Tutorials Hub →
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Primary reference: AlmaLinux ALSA ALSA-2020:4451. Manual pages useful on AlmaLinux 8:
man dnf
man dnf.conf
man systemctl
man journalctl
man firewall-cmd
man semanage
man audit2allow
man kpatch
man sosreport
Other resources: wiki.almalinux.org, Red Hat CVE database, AlmaLinux errata, and per-package notes in /usr/share/doc/tracker/ for components implicated in this advisory.