Cis Ubuntu1204 V110 2 14

Add nodev Option to /run/shm Partition

cyberstrikeus Updated

File contents

2.14 Add nodev Option to /run/shm Partition (Scored)

Profile Applicability

  • Level 1

Description

The nodev mount option specifies that the /run/shm (temporary filesystem stored in memory) cannot contain block or character special devices.

Rationale

Since the /run/shm filesystem is not intended to support devices, set this option to ensure that users cannot attempt to create special devices in /run/shm partitions.

Audit Procedure

Using Command Line

grep /run/shm /etc/fstab | grep nodev
mount | grep /run/shm | grep nodev

Expected Result

Both commands should return output showing nodev is set. If either command emits no output then the system is not configured as recommended.

Remediation

Using Command Line

Edit the /etc/fstab file and add nodev to the fourth field (mounting options of entries that have mount points that contain /run/shm). See the fstab(5) manual page for more information.

mount -o remount,nodev /run/shm

Default Value

By default, the nodev option is not set on the /run/shm partition.

References

  • CIS Ubuntu 12.04 LTS Server Benchmark v1.1.0

Profile

Level 1 - Scored

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-12-04-lts-server-benchmark/cis-ubuntu1204-v110-2-14 commit 2538f49744

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1204-v110-2-14