SV-274178r1120522_rule
V-274178
SRG-OS-000368-GPOS-00154
AZLX-23-002580
CAT II
10
Configure Amazon Linux 2023 so that the /boot/efi directory is mounted with the "nosuid" option.
Modify "/etc/fstab" to use the "nosuid" option on the "/boot/efi" directory.
Verify Amazon Linux 2023 is configured so that the /boot/efi directory is mounted with the "nosuid" option with the following command:
$ mount | grep '\s/boot/efi\s'
/dev/sda1 on /boot/efi type vfat (rw,nosuid,relatime,fmask=0077,dmask=0077,codepage=437,iocharset=ascii,shortname=winnt,errors=remount-ro)
If the /boot/efi file system does not have the "nosuid" option set, this is a finding.
V-274178
False
AZLX-23-002580
Verify Amazon Linux 2023 is configured so that the /boot/efi directory is mounted with the "nosuid" option with the following command:
$ mount | grep '\s/boot/efi\s'
/dev/sda1 on /boot/efi type vfat (rw,nosuid,relatime,fmask=0077,dmask=0077,codepage=437,iocharset=ascii,shortname=winnt,errors=remount-ro)
If the /boot/efi file system does not have the "nosuid" option set, this is a finding.
M
5700