Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-22585 | GEN008740 | SV-26260r1_rule | ECLP-1 | Medium |
Description |
---|
File system extended ACLs provide access to files beyond what is allowed by the mode numbers of the files. If extended ACLs are present on the system's boot loader configuration file(s), these files may be vulnerable to unauthorized access or modification, which could compromise the system's boot process. |
STIG | Date |
---|---|
UNIX SRG | 2013-03-26 |
Check Text ( C-29320r1_chk ) |
---|
If the system does not use GRUB, this is not applicable. Check the grub.conf file for an extended ACL. # ls -lL grub.conf If the listed permissions contain a "+", this file has an extended ACL, and this is a finding. |
Fix Text (F-26352r1_fix) |
---|
Remove the extended ACL from the grub.conf file. |