The Reliable Datagram Sockets (RDS) protocol must be disabled on AIX.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-215394 | SRG-OS-000096-GPOS-00050 | AIX7-00-003089 | SV-215394r958480_rule | 2024-08-16 | 3 |
Description |
---|
The Reliable Datagram Sockets (RDS) protocol is a relatively new protocol developed by Oracle for communication between the nodes of a cluster. Binding this protocol to the network stack increases the attack surface of the host. Unprivileged local processes may be able to cause the system to dynamically load a protocol handler by opening a socket using the protocol. AIX has RDS protocol installed as part of the 'bos.net.tcp.client' fileset. The RDS protocol in primarily used for communication on INFI-Band interfaces. The protocol is manually loaded with the bypassctrl command. To prevent possible attacks this protocol must be disabled unless required. |
ℹ️ Check |
---|
Determine if RDS is currently loaded: # genkex | grep rds If there is any output from the command, this is a finding. |
✔️ Fix |
---|
Configure the system to not automatically load the RDS protocol handler. Check startup scripts for "bypasscrtl load rds" and comment out the "bypassctrl" commands. Unload the driver from the kernel: # bypassctrl unload rds |