1.29 RHEL-09-213050

Information

RHEL 9 must be configured to disable the Controller Area Network kernel module.

GROUP ID: V-257805
RULE ID: SV-257805r1044856

Disabling Controller Area Network (CAN) protects the system against exploitation of any flaws in its implementation.

Solution

To configure the system to prevent the can kernel module from being loaded, add the following lines to the file /etc/modprobe.d/can.conf (or create can.conf if it does not exist):

install can /bin/false
blacklist can

See Also

https://workbench.cisecurity.org/benchmarks/22008

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-257805r1044856_rule, STIG-ID|RHEL-09-213050, Vuln-ID|V-257805

Plugin: Unix

Control ID: fae99b44702d3b9e73bcc2b931efb4dd00bfa57ba1882cad8078c0b8435e6a17