OL6-00-000025 - All device files must be monitored by the system Linux Security Module.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If a device file carries the SELinux type 'unlabeled_t', then SELinux cannot properly restrict access to the device file.

Solution

Device files, which are used for communication with important system resources, should be labeled with proper SELinux types. If any device files carry the SELinux type 'unlabeled_t', investigate the cause and correct the file's context.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V1R17_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(3), CAT|III, CCI|CCI-000366, Group-ID|V-59371, Rule-ID|SV-73801r1_rule, STIG-ID|OL6-00-000025, Vuln-ID|V-59371

Plugin: Unix

Control ID: b2a86d63b44692fe62c0660d729a48497bd8259aa643691f74aa2c2d56a20673