1.1.1.1 Ensure mounting of cramfs filesystems is disabled - lsmod

Information

The cramfs filesystem type is a compressed read-only Linux filesystem embedded in small footprint systems. A cramfs image can be used without having to first decompress the image.

Solution

Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
install cramfs /bin/true

Run the following command to unload the cramfs module:
# rmmod cramfs

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|13

Plugin: Unix

Control ID: 666dffe3f0fb9d946b0d0987f4314239cc574aca3cecae527538c7342fc6e2be