Skip to content

The SUSE operating system must restrict access to the kernel message buffer.

An XCCDF Rule

Description

Restricting access to the kernel message buffer limits access only to root. This prevents attackers from gaining additional system information as a nonprivileged user.

ID
SV-255915r958524_rule
Version
SLES-12-010375
Severity
Low
References
Updated

Remediation Templates

A Manual Procedure

Configure the operating system to restrict access to the kernel message buffer.

Set the system to the required kernel parameter by adding or modifying the following line in /etc/sysctl.conf or a config file in the /etc/sysctl.d/ directory:

     kernel.dmesg_restrict = 1