1.5.4 Ensure prelink is disabled

Information

prelinkis a program that modifies ELF shared libraries and ELF dynamically linked
binaries in such a way that the time needed for the dynamic linker to perform relocations
at startup significantly decreases.

Rationale:

The prelinking feature can interfere with the operation of AIDE, because it changes
binaries. Prelinking can also increase the vulnerability of the system if a malicious user is
able to compromise a common library such as libc.

Solution

Run the following command to restore binaries to normal:

# prelink -ua

Uninstall prelink using the appropriate package manager or manual installation:

# yum remove prelink

# apt-get remove prelink

# zypper remove prelink

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, CSCv6|3.5, CSCv7|14.9

Plugin: Unix

Control ID: 4d72890aee3d3ebe9cf2f16e37144a416fd90cb726cab0f208f5932e6631469f