4.3 Enable Randomized Virtual Memory Region Placement

Information

Set the system flag to force randomized virtual memory region placement. Randomly placing virtual memory regions will make it difficult to write memory page exploits as the memory placement will be consistently shifting.

Solution

Add the following line to the /etc/sysctl.conf file. kernel.randomize_va_space = 2

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv6|3.1

Plugin: Unix

Control ID: 1a8763653847e5d10af15b6821bcb88857ec84762dfa656b76ac432d531e520b