Add nodev Option to Removable Media Partitions
An XCCDF Rule
Description
The nodev
mount option prevents files from being
interpreted as character or block devices.
Legitimate character and block devices should exist only in
the /dev
directory on the root partition or within chroot
jails built for system services.
Add the nodev
option to the list of
Options
in the systemd.mount
unit that
controls mounting of
any removable media partitions.
Rationale
The only legitimate location for device files is the /dev
directory
located on the root partition. An exception to this is chroot jails, and it is
not advised to set nodev
on partitions which contain their root
filesystems.
- ID
- xccdf_org.ssgproject.content_rule_mount_option_nodev_removable_partitions
- Severity
- Medium
- References
- Updated