Cis Ubuntu1604 V200 1 1 1 3

Ensure mounting of jffs2 filesystems is disabled

cyberstrikeus Updated

File contents

Ensure mounting of jffs2 filesystems is disabled

Description

The jffs2 (journaling flash filesystem 2) filesystem type is a log-structured filesystem used in flash memory devices.

Rationale

Removing support for unneeded filesystem types reduces the local attack surface of the system. If this filesystem type is not needed, disable it.

Impact

None noted.

Audit Procedure

Command Line

# modprobe -n -v jffs2 | grep -E '(jffs2|install)'
# lsmod | grep jffs2

Expected Result

install /bin/true

The lsmod command should return no output.

Remediation

Command Line

# Edit or create a file in the /etc/modprobe.d/ directory ending in .conf
# Example: vi /etc/modprobe.d/jffs2.conf
# and add the following line:
install jffs2 /bin/true

# Run the following command to unload the jffs2 module:
rmmod jffs2

Default Value

Not disabled by default.

References

  • CIS Controls Version 7 - 5.1 Establish Secure Configurations: Maintain documented, standard security configuration standards for all authorized operating systems and software.

Profile

Level 1 - Server / Level 1 - Workstation, Assessment: Automated

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-1-1-1-3 commit 18cdd70a39

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-1-1-1-3