SV-217283r646761_rule
V-217283
SRG-OS-000433-GPOS-00192
SLES-12-030320
CAT II
10
Configure the SUSE operating system to prevent leaking of internal kernel addresses by running the following command:
> sudo sysctl -w kernel.kptr_restrict=1
If "1" is not the system's default value, add or update the following line in "/etc/sysctl.d/99-stig.conf":
> sudo sh -c 'echo "kernel.kptr_restrict=1" >> /etc/sysctl.d/99-stig.conf'
> sudo sysctl --system
Verify the SUSE operating system prevents leaking of internal kernel addresses.
Check that the SUSE operating system prevents leaking of internal kernel addresses by running the following command:
> sudo sysctl kernel.kptr_restrict
kernel.kptr_restrict = 1
If the kernel parameter "kptr_restrict" is not equal to "1" or nothing is returned, this is a finding.
V-217283
False
SLES-12-030320
Verify the SUSE operating system prevents leaking of internal kernel addresses.
Check that the SUSE operating system prevents leaking of internal kernel addresses by running the following command:
> sudo sysctl kernel.kptr_restrict
kernel.kptr_restrict = 1
If the kernel parameter "kptr_restrict" is not equal to "1" or nothing is returned, this is a finding.
M
4033