GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required - 'install rds /bin/true'

Information

The RDS protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Solution

Prevent the RDS protocol handler for dynamic loading.
# echo 'install rds /bin/true' >> /etc/modprobe.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, CCI|CCI-000382, Rule-ID|SV-218679r603259_rule, STIG-ID|GEN007480, STIG-Legacy|SV-63451, STIG-Legacy|V-22530, Vuln-ID|V-218679

Plugin: Unix

Control ID: 5da8df293fd3b1efc0a4a0e7c765e58a3ad09f95ce4b4bf26877cb523baed457