1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctl

Information

Randomly placing virtual memory regions will make it difficult to write memory page exploits as the memory placement will be consistently shifting.

Solution

Set the following parameter in the /etc/sysctl.conf file-kernel.randomize_va_space = 2Run the following command to set the active kernel parameter - # sysctl -w kernel.randomize_va_space=2

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv6|3.1

Plugin: Unix

Control ID: 26b28345d786880d6d28d8d03b91321da2cc691bb17536b0a98af234284d7ed4