STIGQter STIGQter: STIG Summary: Oracle Linux 9 Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

OL 9 must be configured to disable the Controller Area Network (CAN) kernel module.

DISA Rule

SV-271444r1091044_rule

Vulnerability Number

V-271444

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

OL09-00-000041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure OL 9 to prevent the can kernel module from being loaded.

Add the following line to the file /etc/modprobe.d/can.conf (or create atm.conf if it does not exist):

install can /bin/false
blacklist can

Check Contents

Verify that OL 9 disables the ability to load the CAN kernel module with the following command:

$ grep -r can /etc/modprobe.conf /etc/modprobe.d/*
install can /bin/false
blacklist can

If the command does not return any output, or the line is commented out, and use of CAN is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Vulnerability Number

V-271444

Documentable

False

Rule Version

OL09-00-000041

Severity Override Guidance

Verify that OL 9 disables the ability to load the CAN kernel module with the following command:

$ grep -r can /etc/modprobe.conf /etc/modprobe.d/*
install can /bin/false
blacklist can

If the command does not return any output, or the line is commented out, and use of CAN is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Check Content Reference

M

Target Key

5680