Check: OL08-00-040380
Oracle Linux 8 STIG:
OL08-00-040380
(in versions v1 r10 through v1 r1)
Title
OL 8 must not have the "iprutils" package installed if not required for operational support. (Cat II impact)
Discussion
The "iprutils" package provides a suite of utilities to manage and configure IBM Power Linux RAID Adapters supported by the IPR SCSI storage device driver. Disabling the "iprutils" package protects the system against exploitation of any flaws in its implementation.
Check Content
Determine if the "iprutils" package is installed with the following command: $ sudo yum list installed iprutils If the "iprutils" package is installed, this is a finding.
Fix Text
Configure OL 8 to disable non-essential capabilities by removing the "iprutils" package from the system with the following command: $ sudo yum remove iprutils
Additional Identifiers
Rule ID: SV-248905r780281_rule
Vulnerability ID: V-248905
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |