STIGQter STIGQter: STIG Summary: Oracle Linux 9 Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

OL 9 SSH daemon must disable remote X connections for interactive users.

DISA Rule

SV-271713r1091851_rule

Vulnerability Number

V-271713

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

OL09-00-002350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the SSH daemon to not allow X11 forwarding.

Add the following line to "/etc/ssh/sshd_config" or to a file in "/etc/ssh/sshd_config.d" or uncomment the line and set the value to "no":

X11Forwarding no

The SSH service must be restarted for changes to take effect:

$ sudo systemctl restart sshd.service

Check Contents

Verify that OL 9 SSH daemon does not allow X11Forwarding with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*x11forwarding'
X11forwarding no

If the value is returned as "yes", the returned line is commented out, or no output is returned, and X11 forwarding is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Vulnerability Number

V-271713

Documentable

False

Rule Version

OL09-00-002350

Severity Override Guidance

Verify that OL 9 SSH daemon does not allow X11Forwarding with the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH '^\s*x11forwarding'
X11forwarding no

If the value is returned as "yes", the returned line is commented out, or no output is returned, and X11 forwarding is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Check Content Reference

M

Target Key

5680