STIGQter STIGQter: STIG Summary: Red Hat Enterprise Linux 10 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories.

DISA Rule

SV-281089r1165622_rule

Vulnerability Number

V-281089

Group Title

SRG-OS-000368-GPOS-00154

Rule Version

RHEL-10-400360

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RHEL 10 to prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories.

Modify "/etc/fstab" to use the "nosuid" option on the "/home" directory.

Check Contents

Verify RHEL 10 is configured so that "/home" is mounted with the "nosuid" option with the following command:

Note: If a separate file system has not been created for the user home directories (user home directories are mounted under "/"), this is automatically a finding, as the "nosuid" option cannot be used on the "/" system.

$ mount | grep /home
/dev/mapper/luks-ca2261ed-7b00-4b7b-84cd-8cd6d8fa4b28 on /home type xfs (rw,nodev,nosuid,noexec,seclabel)

If the "/home" file system is mounted without the "nosuid" option, this is a finding.

Vulnerability Number

V-281089

Documentable

False

Rule Version

RHEL-10-400360

Severity Override Guidance

Verify RHEL 10 is configured so that "/home" is mounted with the "nosuid" option with the following command:

Note: If a separate file system has not been created for the user home directories (user home directories are mounted under "/"), this is automatically a finding, as the "nosuid" option cannot be used on the "/" system.

$ mount | grep /home
/dev/mapper/luks-ca2261ed-7b00-4b7b-84cd-8cd6d8fa4b28 on /home type xfs (rw,nodev,nosuid,noexec,seclabel)

If the "/home" file system is mounted without the "nosuid" option, this is a finding.

Check Content Reference

M

Target Key

5733