Skip to content

The Reliable Datagram Sockets (RDS) protocol must be disabled on AIX.

An XCCDF Rule

Description

<VulnDiscussion>The Reliable Datagram Sockets (RDS) protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol. AIX has RDS protocol installed as part of the 'bos.net.tcp.client' fileset. The RDS protocol in primarily used for communication on INFI-Band interfaces. The protocol is manually loaded with the bypassctrl command. To prevent possible attacks this protocol must be disabled unless required.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-215394r508663_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Configure the system to not automatically load the RDS protocol handler. 

Check startup scripts for "bypasscrtl load rds" and comment out the "bypassctrl" commands.

Unload the driver from the kernel: 
# bypassctrl unload rds