Skip to content

Add nosuid Option to /home

An XCCDF Rule

Description

The nosuid mount option can be used to prevent execution of setuid programs in /home. The SUID and SGID permissions should not be required in these user data directories. Add the nosuid option to the list of Options in the systemd.mount unit that controls mounting of /home.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from user home directory partitions.

ID
xccdf_org.ssgproject.content_rule_mount_option_home_nosuid
Severity
Medium
References
Updated