RHEL 10 must not have the unbound package installed.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-280948SRG-OS-000095-GPOS-00049RHEL-10-200060SV-280948r1197218_rule2026-03-111

Description

If the system is not a Domain Name Server (DNS), it should not have a DNS server package installed to decrease the attack surface of the system.

ℹ️ Check

Verify RHEL 10 does not have a DNS package installed with the following command: $ sudo dnf list --installed unbound Error: No matching Packages to list If the "unbound" package is installed, and the information system security officer lacks a documented requirement for a DNS, this is a finding.

✔️ Fix

Configure RHEL 10 to not have the unbound package installed with the following command: $ sudo dnf -y remove unbound