CIS Ubuntu Linux 24.04 LTS Benchmark · Section 7

Ubuntu 24.04 System Maintenance: 2 Checks

Wartiva runs 2 checks for section 7, System Maintenance, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 2 checks on this page

7.2 Local User and Group Settings

Ensure no duplicate UIDs exist

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 7.2

Finding: This account's UID is shared with another account.

Checks whether another account in the account database shares this account's UID.

This rule fails for an account whose UID is also assigned to another account.

Rationale: Accounts must have unique UIDs for accountability; a shared UID lets one account access another account's files and privileges.

Impact: Reassigning a UID requires updating ownership of the affected user's files.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

For each set of accounts sharing a UID, assign a new unique UID to all but one with usermod -u <newUID> <name>.

Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure no duplicate user names exist

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 7.2

Finding: This account's username is shared with another account.

Checks whether another account in the account database uses this account's username.

This rule fails for an account whose username also appears under another UID.

Rationale: Duplicate user names effectively share the first matching UID, so logins can resolve to an unintended identity and shared file access.

Impact: Renaming a user may require updating references to the old name.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

For each duplicated username, rename all but one account to a unique name with usermod -l <newName> <oldName>.

Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)