STIGQter STIGQter: STIG Summary: MariaDB Enterprise 10.x Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Apr 2026:

MariaDB must disable network functions, ports, protocols, and services deemed by the organization to be nonsecure, in accord with the Ports, Protocols, and Services Management (PPSM) guidance.

DISA Rule

SV-253734r961470_rule

Vulnerability Number

V-253734

Group Title

SRG-APP-000383-DB-000364

Rule Version

MADB-10-008100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To verify that mariadb system denies specific network functions, locate cnf file and specifically bind ip address to deny (or port):
$ ls -la /etc | grep my.cnf
-rw-r--r--.   1 root root      301 Aug 25 12:45 my.cnf
bind-address = 127.0.0.1 #just an example

To specifically change default port (3306) is something different: port = 1234
bind = 10.10.10.10 #as an example

After making changes to the .cnf file, stop and restart the database service.

Check Contents

Check the ports in use by running the following command as the administrator user:

MariaDB > SHOW GLOBAL VARIABLES LIKE 'port';

If the currently defined port configuration is deemed prohibited, this is a finding.

Vulnerability Number

V-253734

Documentable

False

Rule Version

MADB-10-008100

Severity Override Guidance

Check the ports in use by running the following command as the administrator user:

MariaDB > SHOW GLOBAL VARIABLES LIKE 'port';

If the currently defined port configuration is deemed prohibited, this is a finding.

Check Content Reference

M

Target Key

5475