Bug 2005899

Summary: Add blacklist of fuse kernel module in OSPP profile as mitigation of CVE-2021-28950
Product: Red Hat Enterprise Linux 8 Reporter: Jan Pazdziora <jpazdziora>
Component: scap-security-guideAssignee: Vojtech Polasek <vpolasek>
Status: CLOSED WONTFIX QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.4CC: ggasparb, jpazdziora, mhaicman, wsato
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-06 08:34:02 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Pazdziora 2021-09-20 12:48:24 UTC
Description of problem:

Bug https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2021-28950 tracks https://access.redhat.com/security/cve/CVE-2021-28950 in fuse kernel module, making it show up on vulnerability assessment report.

Since FUSE is not part of RHEL 8 Common Criteria certification plan and the issue will be addresses only in RHEL 8.5 via rebase of fuse module to upstream 5.12 via bug 1949873, blacklisting the module in OSPP profile in RHEL 8.4 is a reasonable mitigation.

Please add a rule to OSPP profile in scap-security-guide in RHEL 8.4 to blacklist the fuse kernel module, using the standard blacklisting mechanism that the SCAP content uses.

Version-Release number of selected component (if applicable):

scap-security-guide-0.1.54-5.el8.noarch

How reproducible:

Deterministic.

Steps to Reproduce:
1. Provision RHEL 8.4 system with kickstart addon like

%addon org_fedora_oscap
  content-type = scap-security-guide
  profile = ospp
%end

   or remediate the provisioned system with the ospp profile.
2. Try to load the fuse kernel module:
   # modprobe fuse
3. Check if the module got loaded:
   # lsmod | grep fuse

Actual results:

fuse                  151552  1

Expected results:

No output.

Additional info:

Comment 2 Jan Pazdziora 2021-10-06 08:34:02 UTC
Since blacklisting the kernel module for the CVE is a mitigation and not general hardening, it should not be part of the SCAP profile.