V-38596: The system must implement virtual address space randomization. ----------------------------------------------------------------------- Address space layout randomization (ASLR) makes it more difficult for an attacker to predict the location of attack code he or she has introduced into a process's address space during an attempt at exploitation. Additionally, ASLR also makes it more difficult for an attacker to know the location of existing code in order to repurpose it using return oriented programming (ROP) techniques. Details: `V-38596 in STIG Viewer`_. .. _V-38596 in STIG Viewer: https://www.stigviewer.com/stig/red_hat_enterprise_linux_6/2015-05-26/finding/V-38596 Notes for deployers ~~~~~~~~~~~~~~~~~~~ .. include:: developer-notes/V-38596.rst