4.3 Enable Randomized Virtual Memory Region Placement

Information

Set the system flag to force randomized virtual memory region placement.

*Rationale*

Randomly placing virtual memory regions will make it difficult to write memory page
exploits as the memory placement will be consistently shifting.

Solution

Add the following line to the /etc/sysctl.conf file.kernel.randomize_va_space = 2

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-30(2)

Plugin: Unix

Control ID: 0405a5db7aa25ff59b92239e0bf0d39a7e841f46833ee5ed4bd98cf094076aa1