STIGUI
V-282620CAT II — Medium severitySV-282620r1200840_rule

TOSS 5 must disable virtual system calls.

Rule version TOSS-05-000029 · STIG v1 · 2026-08-20

Discussion

System calls are special routines in the Linux kernel which userspace applications ask to do privileged tasks. Invoking a system call is an expensive operation because the processor must interrupt the currently executing task, switch context to kernel mode, and then back to userspace after the system call completes. Virtual system calls map into user space a page that contains some variables and the implementation of some system calls. This allows the system calls to be executed in userspace to alleviate the context switching expense.

Virtual system calls provide an opportunity of attack for a user who has control of the return instruction pointer. Disabling virtual system calls help to prevent return-oriented programming (ROP) attacks via buffer overflows and overruns. If the system intends to run containers based on RHEL 6 components, then virtual system calls must be enabled for the components to function properly.

Check

Verify the current GRUB 2 configuration disables virtual system calls using the following command:

$ sudo grubby --info=ALL | grep args | grep -v 'vsyscall=none'

If any output is returned and is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.

Fix

Document the use of virtual system calls with the ISSO as an operational requirement or disable them using the following command:

$ sudo grubby --update-kernel=ALL --args="vsyscall=none"

Add or modify the following line in "/etc/default/grub" to ensure the configuration survives kernel updates:

GRUB_CMDLINE_LINUX="vsyscall=none"

Identifiers

Group ID
V-282620
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282620r1200840_rule
Check ID
C-87181r1200838_chk
Fix ID
F-87086r1200839_fix