Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-51005 | OL6-00-000127 | SV-65211r2_rule | Medium |
Description |
---|
Disabling TIPC protects the system against exploitation of any flaws in its implementation. |
STIG | Date |
---|---|
Oracle Linux 6 Security Technical Implementation Guide | 2019-03-20 |
Check Text ( C-53447r2_chk ) |
---|
If the system is configured to prevent the loading of the "tipc" kernel module, it will contain lines inside any file in "/etc/modprobe.d" or the deprecated"/etc/modprobe.conf". These lines instruct the module loading system to run another program (such as "/bin/true") upon a module "install" event. Run the following command to search for such lines in all files in "/etc/modprobe.d" and the deprecated "/etc/modprobe.conf": $ grep -r tipc /etc/modprobe.conf /etc/modprobe.d | grep -i “/bin/true” If no line is returned, this is a finding. |
Fix Text (F-55809r1_fix) |
---|
The Transparent Inter-Process Communication (TIPC) protocol is designed to provide communications between nodes in a cluster. To configure the system to prevent the "tipc" kernel module from being loaded, add the following line to a file in the directory "/etc/modprobe.d": install tipc /bin/true |