GEN007720 - The IPv6 protocol handler must be prevented from dynamic loading unless needed.

Information

IPv6 is the next generation of the Internet protocol. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Solution

There is not an option to not load IPv6.
Remove unnecessary IPv6 addresses from network interfaces via smit.
#smit chinet6

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4, CAT|II, CCI|CCI-001551, Rule-ID|SV-38922r1_rule, STIG-ID|GEN007720, Vuln-ID|V-22542

Plugin: Unix

Control ID: ff8ca7759dc92d92aeba3c16a88d3eec93a3f9e35818269cbdc187137f675e78