STIGQter STIGQter: STIG Summary: Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Ubuntu 22.04 LTS must generate system journal entries without revealing information that could be exploited by adversaries.

DISA Rule

SV-260490r1069105_rule

Vulnerability Number

V-260490

Group Title

SRG-OS-000205-GPOS-00083

Rule Version

UBTU-22-232027

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Ubuntu 22.04 LTS to set the appropriate permissions to the files and directories used by the systemd journal:

Add or modify the following lines in the "`/usr/lib/tmpfiles.d/systemd.conf" file:
z /run/log/journal 2750 root systemd-journal - -
Z /run/log/journal/%m ~2750 root systemd-journal - -
z /var/log/journal 2750 root systemd-journal - -
z /var/log/journal/%m 2750 root systemd-journal - -
z /var/log/journal/%m/system.journal 0640 root systemd-journal - -

Restart the system for the changes to take effect.

Check Contents

Verify the /run/log/journal and /var/log/journal directories have permissions set to "2750" or less permissive by using the following command:

$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %a" {} \;
/run/log/journal 2750
/var/log/journal 2750
/var/log/journal/3b018e681c904487b11671b9c1987cce 2750

If any output returned has a permission set greater than "2750", this is a finding.

Verify all files in the /run/log/journal and /var/log/journal directories have permissions set to "640" or less permissive by using the following command:

$ sudo find /run/log/journal /var/log/journal -type f -exec stat -c "%n %a" {} \;
/var/log/journal/3b018e681c904487b11671b9c1987cce/system@99dcc72bb1134aaeae4bf157aa7606f4-0000000000003c7a-0006073f8d1c0fec.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce/system.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce/user-1000.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce/user-1000@bdedf14602ff4081a77dc7a6debc8626-00000000000062a6-00060b4b414b617a.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce

If any output returned has a permission set greater than "640", this is a finding.

Vulnerability Number

V-260490

Documentable

False

Rule Version

UBTU-22-232027

Severity Override Guidance

Verify the /run/log/journal and /var/log/journal directories have permissions set to "2750" or less permissive by using the following command:

$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %a" {} \;
/run/log/journal 2750
/var/log/journal 2750
/var/log/journal/3b018e681c904487b11671b9c1987cce 2750

If any output returned has a permission set greater than "2750", this is a finding.

Verify all files in the /run/log/journal and /var/log/journal directories have permissions set to "640" or less permissive by using the following command:

$ sudo find /run/log/journal /var/log/journal -type f -exec stat -c "%n %a" {} \;
/var/log/journal/3b018e681c904487b11671b9c1987cce/system@99dcc72bb1134aaeae4bf157aa7606f4-0000000000003c7a-0006073f8d1c0fec.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce/system.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce/user-1000.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce/user-1000@bdedf14602ff4081a77dc7a6debc8626-00000000000062a6-00060b4b414b617a.journal 640
/var/log/journal/3b018e681c904487b11671b9c1987cce

If any output returned has a permission set greater than "640", this is a finding.

Check Content Reference

M

Target Key

5594