STIGUI
V-282553CAT II — Medium severitySV-282553r1200639_rule

TOSS 5 must enable kernel parameters to enforce discretionary access control on hardlinks.

Rule version TOSS-05-000102 · STIG v1 · 2026-08-20

Discussion

By enabling the "fs.protected_hardlinks" kernel parameter, users can no longer create soft or hard links to files they do not own. Disallowing such hardlinks mitigates vulnerabilities based on insecure file system accessed by privileged programs, avoiding an exploitation vector exploiting unsafe use of open() or creat().

Satisfies: SRG-OS-000312-GPOS-00123, SRG-OS-000324-GPOS-00125

Check

Verify TOSS 5 is configured to enable DAC on hardlinks using the following command:

$ sudo sysctl fs.protected_hardlinks

fs.protected_hardlinks = 1

If "fs.protected_hardlinks" is not set to "1" or is missing, this is a finding.

Fix

Configure TOSS 5 to enable DAC on hardlinks with the following:

Add or edit the following line in a system configuration file in the "/etc/sysctl.d/" directory:

fs.protected_hardlinks = 1

Load settings from all system configuration files using the following command:

$ sudo sysctl --system

Identifiers

Group ID
V-282553
Group title
SRG-OS-000312-GPOS-00123
Rule ID
SV-282553r1200639_rule
Check ID
C-87114r1200637_chk
Fix ID
F-87019r1200638_fix