UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The Stream Control Transmission Protocol (SCTP) must be disabled unless required.


Overview

Finding ID Version Rule ID IA Controls Severity
V-208867 OL6-00-000125 SV-208867r505921_rule Medium
Description
Disabling SCTP protects the system against exploitation of any flaws in its implementation.
STIG Date
Oracle Linux 6 Security Technical Implementation Guide 2020-09-10

Details

Check Text ( C-9120r357581_chk )
If the system is configured to prevent the loading of the "sctp" kernel module, it will contain lines inside any file in "/etc/modprobe.d" or the deprecated"/etc/modprobe.conf". These lines instruct the module loading system to run another program (such as "/bin/true") upon a module "install" event. Run the following command to search for such lines in all files in "/etc/modprobe.d" and the deprecated "/etc/modprobe.conf":

$ grep -r sctp /etc/modprobe.conf /etc/modprobe.d | grep -i “/bin/true”

If no line is returned, this is a finding.
Fix Text (F-9120r357582_fix)
The Stream Control Transmission Protocol (SCTP) is a transport layer protocol, designed to support the idea of message-oriented communication, with several streams of messages within one connection. To configure the system to prevent the "sctp" kernel module from being loaded, add the following line to a file in the directory "/etc/modprobe.d":

install sctp /bin/true