summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--factory-default/sys-apps/baselayout/etc/sysctl.conf4
1 files changed, 4 insertions, 0 deletions
diff --git a/factory-default/sys-apps/baselayout/etc/sysctl.conf b/factory-default/sys-apps/baselayout/etc/sysctl.conf
index 7e0d51fc..d3754c81 100644
--- a/factory-default/sys-apps/baselayout/etc/sysctl.conf
+++ b/factory-default/sys-apps/baselayout/etc/sysctl.conf
@@ -43,6 +43,10 @@ fs.protected_symlinks = 1
# the source file
fs.protected_hardlinks = 1
+# Any process which has changed privilege levels or is execute only will not
+# be dumped
+fs.suid_dumpable = 0
+
# Uses a "never overcommit" policy that attempts to prevent any overcommit
# of memory
vm.overcommit_memory = 2