SELinux root exploit
github.com
github.com
The point Sebastian (stealth) is making is fairly balanced: SELinux is very useful, but it's not the catch-all solution to containing root exploits; it even has bugs in its implementations and policies, like all software.
"The setroubleshootd daemon which runs as root, activated by its DBUS activation file when sedispatch was forwarding its AVC denial message, straight passes the pathname to a shell without further sanitization."