4.3 Enable Randomized Virtual Memory Region Placement

Information

Set the system flag to force randomized virtual memory region placement.

*Rationale*

Randomly placing virtual memory regions will make it difficult to write memory page
exploits as the memory placement will be consistently shifting.

Solution

Add the following line to the /etc/sysctl.conf file.kernel.randomize_va_space = 2

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-30(2)

Plugin: Unix

Control ID: 61aca3e399e9069bf2657d982340f8d4f6a611544c2b6b34f42912f00f5fc671