GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required - 'install rds /bin/true'

Information

The RDS protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Solution

Prevent the RDS protocol handler for dynamic loading.
# echo 'install rds /bin/true' >> /etc/modprobe.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, CCE|CCE-14027-7, CCI|CCI-000382, Group-ID|V-22530, Rule-ID|SV-37603r1_rule, STIG-ID|GEN007480, Vuln-ID|V-22530

Plugin: Unix

Control ID: 166cf82b24616110175ee10fffe550f651b9ba65a85a7345fdd7702580c61cca