Public bug reported:
1) Ubuntu 26.04
2) 5.0.2-0ubuntu1~26.04.1
3) Record every creation, replacement, or deletion of a user or system crontab
entry in a system-controlled audit log that ordinary users can read (if
desired) but cannot modify or delete. Only root (or a privileged process)
should be able to alter the log.
Cron is a common persistence mechanism. A process running as a normal user can
install or change a crontab, yet most systems provide little or no durable,
user-immutable record of who created or modified the schedule. Existing cron
execution logs only show when jobs ran, not when the schedule itself was
changed. A user-controlled log file can be deleted or altered by the same
malware that planted the crontab.
Proposed solution
1. When the privileged crontab utility (or equivalent) installs, replaces, or
removes a crontab, emit a structured audit record containing:
• Timestamp
• Real and effective user
• Action (create / replace / delete)
• Target user
• Optional hash or summary of the new content
2. Store the record in a system-owned location (auditd, journald, or a
dedicated root-only log) that is:
• Readable by the owning user (or by authorized auditors)
• Writable/deletable only by root
3. Optionally extend the same protection to related locations (/etc/cron.d/,
/etc/crontab, etc.).
Benefits
• Clear forensic trail of schedule changes
• Prevents malware running as the user from erasing evidence
• Complements existing cron.allow/cron.deny and auditd watches
• Minimal performance impact (only on crontab modification, not on job
execution)
Implementation notes
Prefer leveraging the existing audit framework (auditd) or adding a lightweight
log call inside the setuid crontab binary. Avoid placing the log under any
user-writable directory.
4) User can modify or delete their event log.
** Affects: apparmor (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2170302
Title:
Feature Request: Tamper-resistant logging of crontab creation and
modification
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2170302/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs