Skip to content

Add nodev Option to Non-Root Local Partitions

An XCCDF Rule

Description

The nodev mount option prevents files from being interpreted as character or block devices. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the list of Options in the systemd.mount unit that controls mounting of any non-root local partitions.

Rationale

The nodev mount option prevents files from being interpreted as character or block devices. The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails, for which it is not advised to set nodev on these filesystems.

ID
xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions
Severity
Medium
References
Updated