Skip to content

AlmaLinux OS 9 must disable the Transparent Inter Process Communication (TIPC) kernel module.

An XCCDF Rule

Description

It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities or services are often overlooked and therefore may remain unsecured. They increase the risk to the platform by providing additional attack vectors. Failing to disconnect unused protocols can result in a system compromise. The TIPC is a protocol that is specially designed for intra-cluster communication. It can be configured to transmit messages either on UDP or directly across Ethernet. Message delivery is sequence guaranteed, loss free and flow controlled. Disabling TIPC protects the system against exploitation of any flaws in its implementation.

ID
SV-269347r1050229_rule
Version
ALMA-09-030270
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

To configure the system to prevent the TIPC kernel module from being loaded, run the following command:

$ cat << EOF | tee /etc/modprobe.d/tipc.conf 
install tipc /bin/false
blacklist tipc
EOF