SV-227922r603266_rule
V-227922
SRG-OS-000480
GEN005900
CAT II
10
Edit /etc/vfstab and add the nosuid option for all NFS file systems. Remount the NFS file systems to make the change take effect.
Check the system for NFS mounts not using the nosuid option.
Procedure:
# mount -v | grep " type nfs " | grep -v nosetuid
OR
# grep nfs /etc/mnttab | grep -v nosuid | grep -v :vold
If the mounted file systems do not have the nosetuid/nosuid option, this is a finding. NOTE: Mount options for the volume management daemon (vold) are controlled by the /etc/rmmount.conf file.
V-227922
False
GEN005900
Check the system for NFS mounts not using the nosuid option.
Procedure:
# mount -v | grep " type nfs " | grep -v nosetuid
OR
# grep nfs /etc/mnttab | grep -v nosuid | grep -v :vold
If the mounted file systems do not have the nosetuid/nosuid option, this is a finding. NOTE: Mount options for the volume management daemon (vold) are controlled by the /etc/rmmount.conf file.
M
4061