1.1.17 Ensure noexec option set on /dev/shm partition

Information

The noexec mount option specifies that the filesystem cannot contain executable binaries. Setting this option on a file system prevents users from executing programs from shared memory. This deters users from introducing potentially malicious software on the system.

Solution

Edit the /etc/fstab file and add noexec to the fourth field (mounting options) for the /dev/shm partition. See the fstab(5) manual page for more information. Run the following command to remount /dev/shm : # mount -o remount,noexec /dev/shm Notes - /dev/shm is not specified in /etc/fstab despite being mounted by default. The following line will implement the recommended /dev/shm mount options in /etc/fstab: tmpfs /dev/shm tmpfs defaults,nodev,nosuid,noexec 0 0

See Also

https://workbench.cisecurity.org/files/2171

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1), CSCv7|2.6

Plugin: Unix

Control ID: d5930b59ca5c631fa689c4a0369d1ac51e477aa313c9cdcb8f30799e552e6d71