SV-230512r627750_rule
V-230512
SRG-OS-000368-GPOS-00154
RHEL-08-040124
CAT II
10
Configure the system so that /tmp is mounted with the "nosuid" option by adding /modifying the /etc/fstab with the following line:
/dev/mapper/rhel-tmp /tmp xfs defaults,nodev,nosuid,noexec 0 0
Verify "/tmp" is mounted with the "nosuid" option:
$ sudo mount | grep /tmp
/dev/mapper/rhel-tmp on /tmp type xfs (rw,nodev,nosuid,noexec,seclabel)
Verify that the "nosuid" option is configured for /tmp:
$ sudo cat /etc/fstab | grep /tmp
/dev/mapper/rhel-tmp /tmp xfs defaults,nodev,nosuid,noexec 0 0
If results are returned and the "nosuid" option is missing, or if /tmp is mounted without the "nosuid" option, this is a finding.
V-230512
False
RHEL-08-040124
Verify "/tmp" is mounted with the "nosuid" option:
$ sudo mount | grep /tmp
/dev/mapper/rhel-tmp on /tmp type xfs (rw,nodev,nosuid,noexec,seclabel)
Verify that the "nosuid" option is configured for /tmp:
$ sudo cat /etc/fstab | grep /tmp
/dev/mapper/rhel-tmp /tmp xfs defaults,nodev,nosuid,noexec 0 0
If results are returned and the "nosuid" option is missing, or if /tmp is mounted without the "nosuid" option, this is a finding.
M
2921