Skip to content

Commit 0d4644e

Browse files
authored
Merge pull request #193 from dev-sec/yama_ptrace
Restrict ptrace attach to privileged users
2 parents 09a182b + 9f4f071 commit 0d4644e

1 file changed

Lines changed: 11 additions & 0 deletions

File tree

controls/sysctl_spec.rb

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -432,3 +432,14 @@
432432
its(:value) { should eq 1 }
433433
end
434434
end
435+
436+
control 'sysctl-35' do
437+
impact 1.0
438+
title 'Restrict ptrace attach to privileged users'
439+
desc 'Ensure kernel.yama.ptrace_scope is set to at least 2 so unprivileged users cannot attach ptrace to arbitrary processes.'
440+
# exclude SuSE because it does not have this parameter
441+
only_if { !(container_execution || os.suse?) }
442+
describe kernel_parameter('kernel.yama.ptrace_scope') do
443+
its(:value) { should >= 2 }
444+
end
445+
end

0 commit comments

Comments
 (0)