SV-208848r603263_rule
V-208848
SRG-OS-000480
OL6-00-000078
CAT II
10
To set the runtime status of the "kernel.randomize_va_space" kernel parameter, run the following command:
# sysctl -w kernel.randomize_va_space=2
If this is not the system's default value, add the following line to "/etc/sysctl.conf":
kernel.randomize_va_space = 2
The status of the "kernel.randomize_va_space" kernel parameter can be queried by running the following commands:
$ sysctl kernel.randomize_va_space
$ grep kernel.randomize_va_space /etc/sysctl.conf
The output of the command should indicate a value of at least "1" (preferably "2"). If this value is not the default value, investigate how it could have been adjusted at runtime, and verify it is not set improperly in "/etc/sysctl.conf".
If the correct value is not returned, this is a finding.
V-208848
False
OL6-00-000078
The status of the "kernel.randomize_va_space" kernel parameter can be queried by running the following commands:
$ sysctl kernel.randomize_va_space
$ grep kernel.randomize_va_space /etc/sysctl.conf
The output of the command should indicate a value of at least "1" (preferably "2"). If this value is not the default value, investigate how it could have been adjusted at runtime, and verify it is not set improperly in "/etc/sysctl.conf".
If the correct value is not returned, this is a finding.
M
2928