OL 9 must remove all software components after updated versions have been installed.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-271522OL09-00-000495SV-271522r1091278_ruleCCI-002617low
Description
Previous versions of software components that are not removed from the information system after updates have been installed may be exploited by some adversaries.
STIGDate
Oracle Linux 9 Security Technical Implementation Guide2025-05-08

Details

Check Text (C-271522r1091278_chk)

Verify that OL 9 removes all software components after updated versions have been installed with the following command: $ grep clean /etc/dnf/dnf.conf clean_requirements_on_remove=True If clean_requirements_on_remove is not set to "True", this is a finding.

Fix Text (F-75479r1091277_fix)

Configure OL 9 to remove all software components after updated versions have been installed. Edit the file /etc/dnf/dnf.conf by adding or editing the following line: clean_requirements_on_remove=1