GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required.

Information

The Reliable Datagram Sockets (RDS) protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol.

Satisfies: SRG-OS-000096, SRG-OS-000510

Solution

Remove the RDS protocol handler package.
# pkgrm SUNWrds

OR

Prevent the RDS protocol handler from dynamic loading.
# echo 'exclude: rds' >> /etc/system

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, CCI|CCI-000382, Rule-ID|SV-227958r603266_rule, STIG-ID|GEN007480, STIG-Legacy|SV-26894, STIG-Legacy|V-22530, Vuln-ID|V-227958

Plugin: Unix

Control ID: 75db770a85a6061a498a4716a1ee34a68355614a6461b8de3ac5ea1b7a6be82e