Skip to content

Add noexec Option to /tmp

An XCCDF Rule

Description

The noexec mount option can be used to prevent binaries from being executed out of /tmp. Add the noexec option to the list of Options in the systemd.mount unit that controls mounting of /tmp.

Rationale

Allowing users to execute binaries from world-writable directories such as /tmp should never be necessary in normal operation and can expose the system to potential compromise.

ID
xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec
Severity
Medium
References
Updated