Skip to content

Add nodev Option to Removable Media Partitions

An XCCDF Rule

Description

The nodev mount option prevents files from being interpreted as character or block devices. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the list of Options in the systemd.mount unit that controls mounting of any removable media partitions.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. An exception to this is chroot jails, and it is not advised to set nodev on partitions which contain their root filesystems.

ID
xccdf_org.ssgproject.content_rule_mount_option_nodev_removable_partitions
Severity
Medium
References
Updated