1.329 OL09-00-002500

Information

OL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.

GROUP ID: V-271769
RULE ID: SV-271769r1092019

If an unauthorized or modified device is allowed to exist on the system, there is the possibility the system may perform unintended or unauthorized operations.

Solution

Configure OL 9 to correctly label all system devices.

Restore the SELinux policy for the affected device file from the system policy database using the following command:

$ sudo restorecon -v <device_path>

Substituting "<device_path>" with the path to the affected device file (from the output of the previous commands). An example device file path would be "/dev/ttyUSB0". If the output of the above command does not indicate that the device was relabeled to a more specific SELinux type label, then the SELinux policy of the system must be updated with more specific policy for the device class specified. If a package was used to install support for a device class, that package could be reinstalled using the following command:

$ sudo dnf reinstall -y <package_name>

If a package was not used to install the SELinux policy for a given device class, then it must be generated manually and provide specific type labels.

See Also

https://workbench.cisecurity.org/benchmarks/27024