02

Enable YAMA
Security Module

Enable CONFIG_SECURITY_YAMA in your kernel config.

Set /proc/sys/kernel/yama to either:

  • “1”:  Only child processes can be debugged
  • “2”:  Only processes with CAP_SYS_PTRACE can debug anymore
  • “3”:  Disable debugging completely (Once set, cannot undo anymore)
#EmbeddedLinuxSecurity
By default, processes with the same effective UID can debug each other, access each other’s memory and register contents. Our tip: Activate the YAMA security module. It provides an option to restrict debug access to processes, further enhancing the security of the system.
Icon with a waving hand

Get in touch

sigma star gmbh
Eduard-Bodem-Gasse 6, 1st floor
6020 Innsbruck | Austria

sigma star gmbh logo