OL 8 must not have the "tuned" package installed if not required for operational support.

STIG ID: OL08-00-040390  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium |  CCI: CCI-000366 |  Vulnerability Id: V-248906 | 

Vulnerability Discussion

"Tuned" is a daemon that uses "udev" to monitor connected devices and statically and dynamically tunes system settings according to a selected profile. Disabling the "tuned" package protects the system against exploitation of any flaws in its implementation.

Check

Determine if the "tuned" package is installed with the following command:

$ sudo yum list installed tuned

If the "tuned" package is installed, this is a finding.

Fix

Configure OL 8 to disable non-essential capabilities by removing the "tuned" package from the system with the following command:

$ sudo yum remove tuned