1.6.2 Configure ExecShield - kernel.exec-shield = 1

Information

Execshield is made up of a number of kernel features to provide protection against buffer overflow attacks. These features include prevention of execution in memory data space, and special handling of text buffers.

Rationale:

Enabling any feature that can protect against buffer overflow attacks enhances the security of the system.

Solution

Add the following line to the /etc/sysctl.conf file.

kernel.exec-shield = 1

Default Value:

OS Default: Yes

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|8.4, CSCv7|5.1

Plugin: Unix

Control ID: 167386d89267da0d026338ab1cf5505d0a277bf6abc7a8d9ee6537c875598110