RHEL 10 must not have the unbound package installed.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-280948RHEL-10-200060SV-280948r1197218_ruleCCI-000381medium
Description
If the system is not a Domain Name Server (DNS), it should not have a DNS server package installed to decrease the attack surface of the system.
STIGDate
Red Hat Enterprise Linux 10 Security Technical Implementation Guide2026-03-11

Details

Check Text (C-280948r1197218_chk)

Verify RHEL 10 does not have a DNS package installed with the following command: $ sudo dnf list --installed unbound Error: No matching Packages to list If the "unbound" package is installed, and the information system security officer lacks a documented requirement for a DNS, this is a finding.

Fix Text (F-85414r1165198_fix)

Configure RHEL 10 to not have the unbound package installed with the following command: $ sudo dnf -y remove unbound