6.5.9 (L1) Host SSH daemon, if enabled, must disable stream local forwarding

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disabling stream local forwarding on the SSH daemon ensures that no Unix domain sockets are forwarded, thus enforcing a security boundary. This measure aids in maintaining the integrity and confidentiality of the system.

Disabling stream local forwarding helps in preventing potential misuse of Unix domain sockets which can be a vector for certain types of attacks or data leaks.

Solution

Impact:

There is no functional impact reported, indicating that disabling stream local forwarding is a safe measure towards enhancing system security without affecting operations.

See Also

https://workbench.cisecurity.org/benchmarks/15784