1.5.3 Ensure prelink is disabled

Information

Prelink is a program that modifies ELF shared libraries and ELF dynamically linked binaries in such a way that the time needed for the dynamic linker to perform relocations at startup significantly decreases.

Rationale:

The prelinking feature can interfere with the operation of AIDE, because it changes binaries. Prelinking can also increase the vulnerability of the system if a malicious user is able to compromise a common library such as libc.

Solution

Run the following commands to restore binaries to normal and uninstall prelink :

# prelink -ua
# yum remove prelink

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, CSCv7|14.9

Plugin: Unix

Control ID: 0afa10196d874f3f4d596e6bd837dd091e2166b7424b3cab0ceb2b495df12a43