1.1.1.7 Ensure mounting of udf filesystems is disabled - /etc/modprobe.d/*

Information

The udf filesystem type is the universal disk format used to implement ISO/IEC 13346 and ECMA-167 specifications. This is an open vendor filesystem type for data storage on a broad range of media. This filesystem type is necessary to support writing DVDs and newer optical disc formats.

Rationale:

Removing support for unneeded filesystem types reduces the local attack surface of the system. If this filesystem type is not needed, disable it.

Solution

Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:

install udf /bin/true

Run the following command to unload the udf module:

# rmmod udf

See Also

https://workbench.cisecurity.org/files/3738

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 6ccfbfecc68af44467b9af6b11cf85cf8daf9c742c35955872c15ecb8ca819f1