RHEL-09-411045 - All RHEL 9 interactive users must have a primary group that exists.

Information

If a user is assigned the Group Identifier (GID) of a group that does not exist on the system, and a group with the GID is subsequently created, the user may have unintended rights to any files associated with the group.

Solution

Configure the system so that all GIDs are referenced in '/etc/passwd' are defined in '/etc/group'.

Edit the file '/etc/passwd' and ensure that every user's GID is a valid GID.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_9_V1R3_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CAT|II, CCI|CCI-000764, Rule-ID|SV-258048r926131_rule, STIG-ID|RHEL-09-411045, Vuln-ID|V-258048

Plugin: Unix

Control ID: c5951f1bc40e07c982ecf7b4f4c9c00ddc6f8490e2ed55f662bc154c70b5a460