Disable Core Dumps
An XCCDF Group
Description
A core dump file is the memory image of an executable program when it was terminated by the operating system due to errant behavior. In most cases, only software developers legitimately need to access these files. The core dump files may also contain sensitive information, or unnecessarily occupy large amounts of disk space.Once a hard limit is set in
/etc/security/limits.conf
, or
to a file within the /etc/security/limits.d/
directory, a
user cannot increase that limit within his or her own session. If access
to core dumps is required, consider restricting them to only
certain users or groups. See the limits.conf
man page for more
information.
The core dumps of setuid programs are further protected. The
sysctl
variable fs.suid_dumpable
controls whether
the kernel allows core dumps from these programs at all. The default
value of 0 is recommended.
- ID
- xccdf_org.ssgproject.content_group_coredumps
- Child Items
- Updated