RHEL-09-213050 - RHEL 9 must be configured to disable the Controller Area Network kernel module.

Information

Disabling Controller Area Network (CAN) protects the system against exploitation of any flaws in its implementation.

Solution

To configure the system to prevent the can kernel module from being loaded, add the following line to the file /etc/modprobe.d/can.conf (or create atm.conf if it does not exist):

install can /bin/false
blacklist can

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_9_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-257805r958478_rule, STIG-ID|RHEL-09-213050, Vuln-ID|V-257805

Plugin: Unix

Control ID: ae547d3f0fe4ae8b77f89fd17e16aa4ec4ddbfea6d6bcc2a4d6ee99bb00ebaa7