OL09-00-002423 - OL 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.

Information

ASLR makes it more difficult for an attacker to predict the location of attack code they have introduced into a process's address space during an attempt at exploitation. Additionally, ASLR makes it more difficult for an attacker to know the location of existing code to repurpose it using return-oriented programming (ROP) techniques.

Solution

Configure OL 9 to implement ASLR to protect its memory from unauthorized code execution.

Add the configuration item with the following command:

$ echo 'kernel.randomize_va_space = 2' | sudo tee /etc/sysctl.d/99-kernel_randomize_va_space.conf

Remove any configurations that conflict with the above from the following locations:

/run/sysctl.d/*.conf
/usr/local/lib/sysctl.d/*.conf
/usr/lib/sysctl.d/*.conf
/lib/sysctl.d/*.conf
/etc/sysctl.conf
/etc/sysctl.d/*.conf

Reload settings from all system configuration files with the following command:

$ sudo sysctl --system

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R6_STIG.zip