Skip to content

Add noexec Option to /var/log

An XCCDF Rule

Description

The noexec mount option can be used to prevent binaries from being executed out of /var/log. Add the noexec option to the list of Options in the systemd.mount unit that controls mounting of /var/log.

Rationale

Allowing users to execute binaries from directories containing log files such as /var/log should never be necessary in normal operation and can expose the system to potential compromise.

ID
xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec
Severity
Medium
References
Updated