6.5.9 (L1) Host SSH daemon, if enabled, must disable stream local forwarding

Information

Disabling stream local forwarding on the SSH daemon ensures that no Unix domain sockets are forwarded, thus enforcing a security boundary. This measure aids in maintaining the integrity and confidentiality of the system.

Disabling stream local forwarding helps in preventing potential misuse of Unix domain sockets which can be a vector for certain types of attacks or data leaks.

Solution

Impact:

There is no functional impact reported, indicating that disabling stream local forwarding is a safe measure towards enhancing system security without affecting operations.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|5.1

Plugin: Unix

Control ID: ee49fef18968d38ff013dac185f781ab24fdee7ad7a6efab0e6c3132f72745af