1.1.1.1 Ensure mounting of cramfs filesystems is disabled - modprobe

Information

The cramfs filesystem type is a compressed read-only Linux filesystem embedded in small footprint systems. A cramfs image can be used without having to first decompress the image.

Solution

Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
install cramfs /bin/true

Run the following command to unload the cramfs module:
# rmmod cramfs

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|13

Plugin: Unix

Control ID: 12f47802d91f3577c459a50d183d7ff83b5527929a2a691a64c094e214279149