All SUSE operating system files and directories must have a valid owner.

STIG ID: SLES-15-040400 |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium |  CCI:  | Vulnerability Id: V-235028

Vulnerability Discussion

Unowned files and directories may be unintentionally inherited if a user is assigned the same User Identifier (UID) as the UID of the unowned files.

Check

Either remove all files and directories from the SUSE operating system that do not have a valid user, or assign a valid user to all unowned files and directories on the system with the "chown" command:

> sudo chown

Fix

Verify that all SUSE operating system files and directories on the system have a valid owner.

Check the owner of all files and directories with the following command:

Note: The value after -fstype must be replaced with the filesystem type. XFS is used as an example.

> sudo find / -fstype xfs -nouser

If any files on the system do not have an assigned owner, this is a finding.