ALMA-09-029940 - AlmaLinux OS 9 must disable mounting of cramfs.

Information

Removing support for unneeded filesystem types reduces the local attack surface of the server.

Compressed ROM/RAM file system (or cramfs) is a read-only file system designed for simplicity and space-efficiency. It is mainly used in embedded and small-footprint systems.

Solution

To configure the system to prevent the cramfs kernel module from being loaded, create a *.conf file in /etc/modprobe.d/ with the following content:

install cramfs /bin/false
blacklist cramfs

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-269344r1050226_rule, STIG-ID|ALMA-09-029940, Vuln-ID|V-269344

Plugin: Unix

Control ID: 65becb2833bddbcfa4e5dc6a2d4979bff7d8446e661e8095b3451d3ed8c9a47b