Skip to content

AlmaLinux OS 9 must restrict access to the kernel message buffer.

An XCCDF Rule

Description

Restricting access to the kernel message buffer limits access to only root. This prevents attackers from gaining additional system information as a nonprivileged user. Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000138-GPOS-00069

ID
SV-269425r1050308_rule
Version
ALMA-09-041050
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure AlmaLinux OS 9 to restrict access to the kernel message buffer with the following command:

$ echo "kernel.dmesg_restrict = 1 > /etc/sysctl.d/60-dmesg.conf"

Load settings from all system configuration files with the following command:

$ sysctl --system