OL 9 must be configured so that a separate file system must be used for user home directories (such as /home or an equivalent).

STIG ID: OL09-00-000003  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium |  CCI: CCI-000366 |  Vulnerability Id: V-271433

Vulnerability Discussion

Ensuring that "/home" is mounted on its own partition enables the setting of more restrictive mount options, and also helps ensure that users cannot trivially fill partitions used for log or audit data storage.

Check

Verify that OL 9 uses a separate file system for user home directories (such as /home or an equivalent) with the following command:

$ mount | grep /home
UUID=fba5000f-2ffa-4417-90eb-8c54ae74a32f on /home type ext4 (rw,nodev,nosuid,noexec,seclabel)

If a separate entry for "/home" is not in use, this is a finding.

Fix

Migrate the "/home" directory onto a separate file system/partition.