SV-281234r1166654_rule
V-281234
SRG-OS-000080-GPOS-00048
RHEL-10-700130
CAT II
10
Configure RHEL 10 to prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot/efi" directory.
Modify "/etc/fstab" to use the "nosuid" option on the "/boot/efi" directory.
To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command:
$ sudo systemctl daemon-reload
Use the following command to apply the changes immediately without a reboot:
$ sudo mount -o remount /boot/efi
Note: For systems that use BIOS and for vfat systems, this requirement is not applicable.
Verify RHEL 10 is configured so that the "/boot/efi "directory is mounted with the "nosuid" option with the following command:
$ mount | grep '\s/boot/efi\s'
/dev/sda1 on /boot/efi type vfat (rw,nosuid,relatime,fmask=0077,dmask=0077,codepage=437,iocharset=ascii,shortname=winnt,errors=remount-ro)
If the "/boot/efi" file system does not have the "nosuid" option set, this is a finding.
V-281234
False
RHEL-10-700130
Note: For systems that use BIOS and for vfat systems, this requirement is not applicable.
Verify RHEL 10 is configured so that the "/boot/efi "directory is mounted with the "nosuid" option with the following command:
$ mount | grep '\s/boot/efi\s'
/dev/sda1 on /boot/efi type vfat (rw,nosuid,relatime,fmask=0077,dmask=0077,codepage=437,iocharset=ascii,shortname=winnt,errors=remount-ro)
If the "/boot/efi" file system does not have the "nosuid" option set, this is a finding.
M
5733