STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.

DISA Rule

SV-281046r1165493_rule

Vulnerability Number

V-281046

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

RHEL-10-400145

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 so that all system device files are correctly labeled to prevent unauthorized modification.

Restore the SELinux policy for the affected device file from the system policy database using the following command:

$ sudo restorecon -v <device_path>

Substitute "<device_path>" with the path to the affected device file (from the output of the previous commands). An example device file path would be "/dev/ttyUSB0".

If the output of the above command does not indicate that the device was relabeled to a more specific SELinux type label, the SELinux policy of the system must be updated with more specific policy for the device class specified.

If a package was used to install support for a device class, that package could be reinstalled using the following command:

$ sudo dnf reinstall <package_name>

If a package was not used to install the SELinux policy for a given device class, it must be generated manually and provide specific type labels.

Check Contents

Verify RHEL 10 is configured so that all system device files are correctly labeled to prevent unauthorized modification.

List all device files on the system that are incorrectly labeled with the following commands:

Note: Device files are normally found under "/dev", but applications may place device files in other directories and may necessitate a search of the entire system.

$ sudo find /dev -context *:device_t:* \( -type c -o -type b \) -printf "%p %Z\n"

$ sudo find /dev -context *:unlabeled_t:* \( -type c -o -type b \) -printf "%p %Z\n"

Note: There are device files, such as "/dev/vmci", that are used when the operating system is a host virtual machine. They will not be owned by a user on the system and require the "device_t" label to operate. These device files are not a finding.

If there is output from either of these commands, other than already noted, this is a finding.

Vulnerability Number

V-281046

Documentable

False

Rule Version

RHEL-10-400145

Severity Override Guidance

Verify RHEL 10 is configured so that all system device files are correctly labeled to prevent unauthorized modification.

List all device files on the system that are incorrectly labeled with the following commands:

Note: Device files are normally found under "/dev", but applications may place device files in other directories and may necessitate a search of the entire system.

$ sudo find /dev -context *:device_t:* \( -type c -o -type b \) -printf "%p %Z\n"

$ sudo find /dev -context *:unlabeled_t:* \( -type c -o -type b \) -printf "%p %Z\n"

Note: There are device files, such as "/dev/vmci", that are used when the operating system is a host virtual machine. They will not be owned by a user on the system and require the "device_t" label to operate. These device files are not a finding.

If there is output from either of these commands, other than already noted, this is a finding.

Check Content Reference

M

Target Key

5733