Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-34680

Two "Disable storing core dumps" exist, each one conflicting on each other

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Undefined Undefined
    • None
    • rhel-9.3.0
    • scap-security-guide
    • None
    • Normal
    • sst_security_compliance
    • ssg_security
    • None
    • False
    • Hide


    • None
    • Red Hat Enterprise Linux
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      When selecting the OSPP profile ("Protection Profile for General Purpose Operating Systems (144)"), xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern_empty_string rule gets selected, while, when selecting STIG profile ("DISA Stig for Red Hat Enterprise Linux 9 (493)"), xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern rule gets selected.


      1. Why do we have two different implementations for the same functionality? (funtionality being disabling core dumps)
      2. Can we deprecate xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern_empty_string implementation because that rule is not robust?
        It's not robust because, as the core(5) manpage states, just having kernel.core_pattern= will still generate core dumps if kernel.core_uses_pid is set to 1 (which is the default):
                •  /proc/sys/kernel/core_pattern  is  empty and /proc/sys/kernel/core_uses_pid contains the value 0.  (These
                  files are described below.)  Note that  if  /proc/sys/kernel/core_pattern  is  empty  and  /proc/sys/ker‐
                  nel/core_uses_pid  contains the value 1, core dump files will have names of the form .pid, and such files
                  are hidden unless one uses the ls(1) -a option.

      Please provide the package NVR for which bug is seen:


      How reproducible:


            vpolasek@redhat.com Vojtech Polasek
            rhn-support-rmetrich Renaud Métrich
            Vojtech Polasek Vojtech Polasek
            SSG Security QE SSG Security QE
            0 Vote for this issue
            6 Start watching this issue
