What Is SELinux?
SELinux stands for Security-Enhanced Linux. Developed by the NSA and released as open source in 2000, it adds Mandatory Access Control (MAC) on top of traditional Linux permissions.
Think of it this way: regular Linux permissions (DAC) let file owners decide who can access what. SELinux adds a second layer where the system policy decides — regardless of what the owner wants.
DAC vs MAC
Traditional Linux uses Discretionary Access Control:
- Access based on user/group identity (uid/gid)
- Owner can change permissions freely
- Root can do almost anything
SELinux adds Mandatory Access Control:
- Access based on labels and policy rules
- Even root is constrained
- Policy defines allowed interactions between types
The key insight: SELinux can deny access even when DAC allows it, but it cannot allow access when DAC denies it.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Why SELinux Matters
Real CVE Protection
SELinux has proven its value against real-world vulnerabilities:
- Log4Shell (CVE-2021-44228) — Critical RCE. SELinux confined the vulnerable Java process, limiting the attacker's reach to sensitive files
- Looney Tunables (CVE-2023-4911) — Privilege escalation via glibc buffer overflow. SELinux policies restricted the elevated process
- Grafana (CVE-2023-3128) — Authentication bypass. SELinux added defense-in-depth
Compliance Requirements
Regulations like NIS2, DORA, and hardening baselines (CIS, DISA STIGs) all recommend or require SELinux in enforcing mode.
The Three Modes
SELinux operates in three modes:
- Enforcing — Policy is applied, violations are blocked and logged
- Permissive — Violations are logged but not blocked (useful for troubleshooting)
- Disabled — SELinux is off entirely (never do this in production)
Check your current mode:
getenforceGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Getting Started
SELinux is enabled by default on RHEL. The targeted policy confines selected services while leaving most user activity unconfined — a practical balance between security and usability.
Want to master SELinux hands-on? Our SELinux for System Admins course walks you through real-world labs on RHEL 9/10 — from labels to booleans to troubleshooting production web servers.
---
Ready to go deeper?
This article is part of a hands-on learning path. Continue building your skills with SELinux for System Admins on CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SELinux DAC vs MAC Explained
Understand the difference between Discretionary and Mandatory Access Control. Learn why MAC stops attacks that DAC cannot prevent.
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
Which Linux Distro in 2026?
The definitive guide to choosing a Linux distribution in 2026. Ranked by use case: beginner, developer, server, gaming, privacy, and old hardware.
Why LLMs Get Your Code Wrong
Understand why AI assistants hallucinate outdated APIs and how Context7's real-time documentation solves the version mismatch problem.
Wolfi Distroless Container Images
Wolfi is a Linux undistro designed for containers with zero CVEs. Learn how Wolfi and Chainguard Images reduce your container attack surface compared.
Explore topics
Browse more articles on the topics covered here.