STIGQter STIGQter: STIG Summary: Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Ubuntu 22.04 LTS must configure the directories used by the system journal to be owned by "root".

DISA Rule

SV-260501r1184052_rule

Vulnerability Number

V-260501

Group Title

SRG-OS-000206-GPOS-00084

Rule Version

UBTU-22-232080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Ubuntu 22.04 LTS to set the appropriate ownership to the directories used by the systemd journal.

Create a drop-in file if it does not already exist with the following command:

$ sudo vi /etc/tmpfiles.d/zzz-systemd-stig.conf

Add or modify the following lines in the "/etc/tmpfiles.d/zzz-systemd-stig.conf" file:

z /run/log/journal 2750 root systemd-journal - -
z /var/log/journal 2750 root systemd-journal - -
z /var/log/journal/%m 2750 root systemd-journal - -

Restart the system for the changes to take effect.

Check Contents

Verify the /run/log/journal and /var/log/journal directories are owned by "root" by using the following command:

$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %U" {} \;
/run/log/journal root
/var/log/journal root
/var/log/journal/3b018e681c904487b11671b9c1987cce root

If any output returned is not owned by "root", this is a finding.

Vulnerability Number

V-260501

Documentable

False

Rule Version

UBTU-22-232080

Severity Override Guidance

Verify the /run/log/journal and /var/log/journal directories are owned by "root" by using the following command:

$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %U" {} \;
/run/log/journal root
/var/log/journal root
/var/log/journal/3b018e681c904487b11671b9c1987cce root

If any output returned is not owned by "root", this is a finding.

Check Content Reference

M

Target Key

5594