RHEL 10 must not have the "nfs-utils" package installed.

STIG ID: RHEL-10-200010  |  SRG: SRG-OS-000095-GPOS-00049 |  Severity: medium (CAT II)  |  CCI: CCI-000381 |  Vulnerability Id: V-280943

Vulnerability Discussion

The "nfs-utils" package provides a daemon for the kernel Network File System (NFS) server and related tools. This package also contains the "showmount" program. The "showmount" program queries the mount daemon on a remote host for information about the NFS server on the remote host. For example, "showmount" can display the clients that are mounted on that host.

Check

Verify RHEL 10 does not have the "nfs-utils" package installed with the following command:

$ sudo dnf list --installed nfs-utils
Error: No matching Packages to list

If the "nfs-utils" package is installed, this is a finding.

Fix

Configure RHEL 10 to not have the "nfs-utils" package installed with the following command:

$ sudo dnf -y remove nfs-utils