STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to Oracle Linux 8 Security Technical Implementation Guide

V-248827

CAT I (High)

OL 8 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.

Rule ID

SV-248827r1134850_rule

STIG

Oracle Linux 8 Security Technical Implementation Guide

Version

V2R8

CCIs

CCI-000381

Discussion

The EPEL is a repository of high-quality open-source packages for enterprise-class Linux distributions such as RHEL, CentOS, AlmaLinux, Rocky Linux, and Oracle Linux. These packages are not part of the official distribution but are built using the same Fedora build system to ensure compatibility and maintain quality standards.

Check Content

Verify that OL 8 is not able to install packages from the EPEL with the following command:

$ dnf repolist
repo id                         repo name
ol8_UEKR7                       Latest Unbreakable Enterprise Kernel Release 7 for Oracle Linux 8 (x86_64)
ol8_appstream                   Oracle Linux 8 Application Stream (x86_64)
ol8_baseos_latest               Oracle Linux 8 BaseOS Latest (x86_64)

If any repositories containing the word "epel" in the name exist, this is a finding.

Fix Text

The repo package can be manually removed with the following command:

$ sudo dnf remove epel-release

Configure OL 8 to disable use of the EPEL repository with the following command:

$ sudo dnf config-manager --set-disabled epel