SV-230276r627750_rule
V-230276
SRG-OS-000433-GPOS-00192
RHEL-08-010420
CAT II
10
The NX bit execute protection must be enabled in the system BIOS.
Verify the NX (no-execution) bit flag is set on the system.
Check that the no-execution bit flag is set with the following commands:
$ sudo dmesg | grep NX
[ 0.000000] NX (Execute Disable) protection: active
If "dmesg" does not show "NX (Execute Disable) protection" active, check the cpuinfo settings with the following command:
$ sudo less /proc/cpuinfo | grep -i flags
flags : fpu vme de pse tsc ms nx rdtscp lm constant_tsc
If "flags" does not contain the "nx" flag, this is a finding.
V-230276
False
RHEL-08-010420
Verify the NX (no-execution) bit flag is set on the system.
Check that the no-execution bit flag is set with the following commands:
$ sudo dmesg | grep NX
[ 0.000000] NX (Execute Disable) protection: active
If "dmesg" does not show "NX (Execute Disable) protection" active, check the cpuinfo settings with the following command:
$ sudo less /proc/cpuinfo | grep -i flags
flags : fpu vme de pse tsc ms nx rdtscp lm constant_tsc
If "flags" does not contain the "nx" flag, this is a finding.
M
2921