File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 317317 end
318318end
319319
320- control 'sysctl-31 ' do
320+ control 'sysctl-31a ' do
321321 impact 1.0
322- title 'Secure Core Dumps'
323- desc 'Ensure that core dumps can never be made by setuid programs or with fully qualified path '
322+ title 'Secure Core Dumps - dump settings '
323+ desc 'Ensure that core dumps can never be made by setuid programs'
324324
325325 describe kernel_parameter ( 'fs.suid_dumpable' ) do
326326 its ( :value ) { should cmp ( /(0|2)/ ) }
327327 end
328+ end
329+
330+ control 'sysctl-31b' do
331+ impact 1.0
332+ title 'Secure Core Dumps - dump path'
333+ desc 'Ensure that core dumps are done with fully qualified path'
334+ only_if { kernel_parameter ( 'fs.suid_dumpable' ) . value == 2 }
335+
328336 describe kernel_parameter ( 'kernel.core_pattern' ) do
329337 its ( :value ) { should match %r{^/.*} }
330338 end
You can’t perform that action at this time.
0 commit comments