Disable Mounting of udf Filesystems

Details

The udf filesystem type is the universal disk format used to implement ISO/IEC 13346 and

ECMA-167 specifications. This is an open vendor filesystem type for data storage on a

broad range of media. This filesystem type is necessary to support writing DVDs and newer

optical disc formats.

*Rationale*

Removing support for unneeded filesystem types reduces the local attack surface of the

server. If this filesystem type is not needed, disable it.

Solution

Edit or create the file /etc/modprobe.d/CIS.conf and add the following line-install udf /bin/true

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles