STIGUI
V-282610CAT II — Medium severitySV-282610r1200810_rule

TOSS 5 must implement nonexecutable data to protect its memory from unauthorized code execution.

Rule version TOSS-05-000114 · STIG v1 · 2026-08-20

Discussion

ExecShield uses the segmentation feature on all x86 systems to prevent execution in memory higher than a certain address. It writes an address as a limit in the code segment descriptor, to control where code can be executed, on a per-process basis. When the kernel places a process's memory regions such as the stack and heap higher than this address, the hardware prevents execution in that address range. This is enabled by default on the latest Red Hat and Fedora systems if supported by the hardware.

Check

Verify ExecShield is enabled on 64-bit TOSS 5 systems using the following command:

$ sudo dmesg | grep '[NX|DX]*protection' 

[ 0.000000] NX (Execute Disable) protection: active

If "dmesg" does not show "NX (Execute Disable) protection" active, this is a finding.

Fix

Update the GRUB 2 bootloader configuration.

Run the following command:

$ sudo grubby --update-kernel=ALL --remove-args=noexec

Identifiers

Group ID
V-282610
Group title
SRG-OS-000433-GPOS-00192
Rule ID
SV-282610r1200810_rule
Check ID
C-87171r1200808_chk
Fix ID
F-87076r1200809_fix