1.1.16 Add noexec Option to /dev/shm Partition

Information

Configuration Level : Level-I

Solution

Edit the /etc/fstab file and add noexec to the fourth field (mounting options). Look for entries that have mount points that contain /dev/shm. See the fstab(5) manual page for more information.# mount -o remount,noexec /dev/shm

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CCE|CCE-14927-8, CSCv6|3.1

Plugin: Unix

Control ID: b4964bed6eef2bda36c16310c3bcd5ff2308f6e95ae4bdd478073f4320e8a7ce