From f040081a5998fddd1ea4bc30140e41c405842371 Mon Sep 17 00:00:00 2001 From: madaidan <50278627+madaidan@users.noreply.github.com> Date: Sun, 30 Jun 2019 00:13:52 +0000 Subject: [PATCH] Prevent setuid processes from creating coredumps. --- etc/sysctl.d/suid_dumpable.conf | 2 ++ 1 file changed, 2 insertions(+) create mode 100644 etc/sysctl.d/suid_dumpable.conf diff --git a/etc/sysctl.d/suid_dumpable.conf b/etc/sysctl.d/suid_dumpable.conf new file mode 100644 index 0000000..1ed3b79 --- /dev/null +++ b/etc/sysctl.d/suid_dumpable.conf @@ -0,0 +1,2 @@ +# Prevent setuid processes from creating coredumps. +fs.suid_dumpable=0