1.1.1.6 Ensure mounting of squashfs filesystems is disabled - modprobe

Information

The squashfs filesystem type is a compressed read-only Linux filesystem embedded in small footprint systems (similar to cramfs ). A squashfs image can be used without having to first decompress the image.

Solution

Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
install squashfs /bin/true

Run the following command to unload the squashfs module:
# rmmod squashfs

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|13

Plugin: Unix

Control ID: 3f2e33853d185816fc0d710d192d3e2b352e7ef81db472e405b9084e6dd7b5e2