RHEL-06-000025 - All device files must be monitored by the system Linux Security Module.

Information

If a device file carries the SELinux type 'unlabeled_t', then SELinux cannot properly restrict access to the device file.

Solution

Device files, which are used for communication with important system resources, should be labeled with proper SELinux types. If any device files carry the SELinux type 'unlabeled_t', investigate the cause and correct the file's context.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), 800-53|AC-6(10), CAT|III, CCI|CCI-002165, CCI|CCI-002235, Rule-ID|SV-217864r603264_rule, STIG-ID|RHEL-06-000025, STIG-Legacy|SV-65589, STIG-Legacy|V-51379, Vuln-ID|V-217864

Plugin: Unix

Control ID: 17eaf7ad54a71f7461a7461a193bf8c5e8926e609f32c2dbfe9ef8c1fd71d6f7