STIGQter STIGQter: STIG Summary: Oracle Linux 8 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

OL 8 must not have the "gssproxy" package installed if not required for operational support.

DISA Rule

SV-248904r1184140_rule

Vulnerability Number

V-248904

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

OL08-00-040370

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure OL 8 to disable nonessential capabilities by removing the "gssproxy" package from the system with the following command:

$ sudo yum remove gssproxy

Check Contents

Note: For Oracle Linux systems, if there is an operational need for gssproxy to be installed, this is not applicable.

Note: If NFS mounts are authorized and in use on the system, this control is not applicable.

Determine if the "gssproxy" package is installed with the following command:

$ sudo yum list installed gssproxy

If the "gssproxy" package is installed, this is a finding.

Vulnerability Number

V-248904

Documentable

False

Rule Version

OL08-00-040370

Severity Override Guidance

Note: For Oracle Linux systems, if there is an operational need for gssproxy to be installed, this is not applicable.

Note: If NFS mounts are authorized and in use on the system, this control is not applicable.

Determine if the "gssproxy" package is installed with the following command:

$ sudo yum list installed gssproxy

If the "gssproxy" package is installed, this is a finding.

Check Content Reference

M

Target Key

5416