# Cis Ubuntu1604 V200 1 5 2

> Ensure address space layout randomization (ASLR) is enabled

- Skill: `cyberstrikeus/cis-ubuntu1604-v200-1-5-2` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-1-5-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu1604-v200-1-5-2/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu1604-v200-1-5-2

---


# CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - 1.5.2

## Profile Applicability

- Level 1 - Server
- Level 1 - Workstation

## Description

Address space layout randomization (ASLR) is an exploit mitigation technique which randomly arranges the address space of key data areas of a process.

## Rationale

Randomly placing virtual memory regions will make it difficult to write memory page exploits as the memory placement will be consistently shifting.

## Audit Procedure

### Command Line

Run the following commands and verify output matches:

```bash
sysctl kernel.randomize_va_space
```

Expected output: `kernel.randomize_va_space = 2`

```bash
grep -Es "^\s*kernel\.randomize_va_space\s*=\s*([0-1]|[3-9]|[1-9][0-9]+)" /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /run/sysctl.d/*.conf
```

Nothing should be returned.

## Expected Result

`kernel.randomize_va_space` should be set to `2`. No overriding configurations should exist in sysctl configuration files.

## Remediation

### Command Line

Set the following parameter in `/etc/sysctl.conf` or a `/etc/sysctl.d/*` file ending in `.conf`:

```
kernel.randomize_va_space = 2
```

Run the following script to comment out entries that override the default setting of kernel.randomize_va_space:

```bash
#!/usr/bin/bash

for file in /etc/sysctl.conf /etc/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /run/sysctl.d/*.conf; do
   if [ -f "$file" ]; then
      grep -Esq "^\s*kernel\.randomize_va_space\s*=\s*([0-1]|[3-9]|[1-9][0-9]+)" "$file" && sed -ri 's/^\s*kernel\.randomize_va_space\s*=\s*([0-1]|[3-9]|[1-9][0-9]+)/# &/gi' "$file"
   fi
done
```

Run the following command to set the active kernel parameter:

```bash
sysctl -w kernel.randomize_va_space=2
```

## Additional Information

Configuration files are read from directories in `/etc/`, `/run/`, `/usr/local/lib/`, and `/lib/`, in order of precedence. Files must have the ".conf" extension. Files in `/etc/` override files with the same name in `/run/`, `/usr/local/lib/`, and `/lib/`. Files in `/run/` override files with the same name under `/usr/`.

## Default Value

kernel.randomize_va_space = 2

## References

1. http://manpages.ubuntu.com/manpages/focal/man5/sysctl.d.5.html

## CIS Controls

| Controls Version | Control                                                                                  |
| ---------------- | ---------------------------------------------------------------------------------------- |
| v7               | 8.3 Enable Operating System Anti-Exploitation Features/ Deploy Anti-Exploit Technologies |

## Assessment Status

Automated

