AlmaLinux OS 9 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-269352 | ALMA-09-030820 | SV-269352r1134829_rule | CCI-000381 | medium |
| Description | ||||
| The EPEL is a repository of high-quality open-source packages for enterprise-class Linux distributions such as RHEL, CentOS, AlmaLinux, Rocky Linux, and Oracle Linux. These packages are not part of the official distribution but are built using the same Fedora build system to ensure compatibility and maintain quality standards. | ||||
| STIG | Date | |||
| Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide | 2026-02-27 | |||
Details
Check Text (C-269352r1134829_chk)
Verify that AlmaLinux OS 9 is not able to install packages from the EPEL with the following command:
$ dnf repolist
repo id repo name
appstream AlmaLinux 9 - AppStream
baseos AlmaLinux 9 - BaseOS
extras AlmaLinux 9 - Extras
If any repositories containing the word "epel" in the name exist, this is a finding.
Fix Text (F-73284r1134828_fix)
The repo package can be manually removed with the following command:
$ sudo dnf remove epel-release
Configure AlmaLinux 9 to disable use of the EPEL repository with the following command:
$ sudo dnf config-manager --set-disabled epel