GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required.

Information

The Reliable Datagram Sockets (RDS) protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Solution

Configure the system to not automatically load the RDS protocol handler.

Check startup scripts for 'bypassctrl load rds' and comment out the bypassctrl commands.

Unload the driver from the kernel.
# bypassctrl unload rds

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, CCI|CCI-000382, Group-ID|V-22530, Rule-ID|SV-38913r1_rule, STIG-ID|GEN007480, Vuln-ID|V-22530

Plugin: Unix

Control ID: edadfcef718722b2db8bd82932d9e51a6ac54d9e284da6bb9ebf7a75fbab4e2a