GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required - 'install rds /bin/true'

Information

The RDS protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Solution

Prevent the RDS protocol handler for dynamic loading.
# echo 'install rds /bin/true' >> /etc/modprobe.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000382, Rule-ID|SV-63451r1_rule, STIG-ID|GEN007480, Vuln-ID|V-22530

Plugin: Unix

Control ID: c11bd68786d2bbabb2ec53b2653b302121e02a88289be53cbd8a541d3f06ad84