RHEL-09-213050 - RHEL 9 must be configured to disable the Controller Area Network kernel module.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disabling Controller Area Network (CAN) protects the system against exploitation of any flaws in its implementation.

Solution

To configure the system to prevent the can kernel module from being loaded, add the following line to the file /etc/modprobe.d/can.conf (or create atm.conf if it does not exist):

install can /bin/false
blacklist can

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/U_RHEL_9_V1R1_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000381, Rule-ID|SV-257805r925402_rule, STIG-ID|RHEL-09-213050, Vuln-ID|V-257805

Plugin: Unix

Control ID: c37299e35df787f6cf13f09c009f449d4fb7b428326bc3dd3a927c15e6ac2b06