SV-230280r627750_rule
V-230280
SRG-OS-000433-GPOS-00193
RHEL-08-010430
CAT II
10
Configure the operating system to implement virtual address space randomization.
Set the system to the required kernel parameter by adding the following line to "/etc/sysctl.d/*.conf"(or modify the line to have the required value):
kernel.randomize_va_space=2
Issue the following command to make the changes take effect:
$ sudo sysctl --system
Verify RHEL 8 implements ASLR with the following command:
$ sudo sysctl kernel.randomize_va_space
kernel.randomize_va_space = 2
If nothing is returned, verify the kernel parameter "randomize_va_space" is set to "2" with the following command:
$ sudo cat /proc/sys/kernel/randomize_va_space
2
If "kernel.randomize_va_space" is not set to "2", this is a finding.
V-230280
False
RHEL-08-010430
Verify RHEL 8 implements ASLR with the following command:
$ sudo sysctl kernel.randomize_va_space
kernel.randomize_va_space = 2
If nothing is returned, verify the kernel parameter "randomize_va_space" is set to "2" with the following command:
$ sudo cat /proc/sys/kernel/randomize_va_space
2
If "kernel.randomize_va_space" is not set to "2", this is a finding.
M
2921