How to Harden Linux Server Security by Securing Filesystem Mount Options for /tmp, /dev/shm, and /proc on Ubuntu Server

Knowing how to harden Linux server security by securing filesystem mount options for /tmp, /dev/shm, and /proc on Ubuntu Server is one of the most effective ways to reduce your attack surface. These three directories are common targets for attackers. They can be used to execute malicious scripts, escalate privileges, or hide harmful processes. By controlling how these filesystems are mounted, you take away key tools that attackers rely on. This tutorial walks you through each step clearly. You’ll learn what mount options like noexec, nosuid, and nodev do. You’ll also learn exactly how to apply them to /tmp, /dev/shm, and /proc. These changes are low-risk, high-impact, and suitable for any Ubuntu Server running production workloads. Whether you manage a VPS, a dedicated server, or a cloud instance, this guide applies to you.

Prerequisites and Requirements for Securing Linux Filesystem Mount Options

Before you start, make sure you meet these requirements. This guide is written for Ubuntu Server 20.04 or 22.04 LTS. The steps should also work on Ubuntu 18.04 with minor differences.

You will need:

– Root or sudo access to your server
– SSH access to a terminal session
– Basic familiarity with editing files using nano or vim
– A backup or snapshot of your server (strongly recommended before editing /etc/fstab)

Estimated time to complete: 20 to 30 minutes.

You should understand what /etc/fstab is. It controls how filesystems are mounted at boot. Editing it incorrectly can prevent your server from booting. Always double-check your syntax before rebooting. If you’re working on a remote VPS, make sure you have console access through your hosting provider’s dashboard as a fallback.

You don’t need any additional software. Everything in this guide uses tools built into Ubuntu Server.

How to Harden Linux Server Security by Securing /tmp, /dev/shm, and /proc Mount Options

For a related walkthrough, see: How to Install and Configure Docker on Ubuntu Server 24.04 Lts

Follow these steps carefully. Each one is explained so you understand what’s happening and why.

Step 1: Back up your current /etc/fstab file

Before making any changes, create a backup of your existing fstab file.

sudo cp /etc/fstab /etc/fstab.bak

This gives you a restore point if something goes wrong.

Step 2: Check your current /tmp mount configuration

Run this command to see if /tmp is already a separate partition or uses tmpfs.

mount | grep /tmp

If you see no output, /tmp is part of your root filesystem. You’ll need to add a tmpfs entry for it in /etc/fstab.

Step 3: Secure the /tmp filesystem

Open /etc/fstab with a text editor.

sudo nano /etc/fstab

Add this line at the bottom. If a /tmp entry already exists, modify it instead of adding a new one.

tmpfs /tmp tmpfs defaults,noexec,nosuid,nodev,size=512M 0 0

Here’s what each option does:

– noexec , prevents execution of binaries stored in /tmp
– nosuid , ignores setuid bits, blocking privilege escalation
– nodev , prevents device files from being created
– size=512M , limits the tmpfs size to 512 megabytes

Save the file and exit. Then remount /tmp without rebooting.

sudo mount -o remount /tmp

Verify the options are active.

mount | grep /tmp

You should see noexec, nosuid, and nodev in the output.

Step 4: Secure the /dev/shm filesystem

/dev/shm is shared memory. It’s a common location for attackers to drop and execute payloads. Open /etc/fstab again and add or modify the /dev/shm entry.

tmpfs /dev/shm tmpfs defaults,noexec,nosuid,nodev 0 0

Save the file. Then remount it.

sudo mount -o remount /dev/shm

Confirm the mount options are applied.

mount | grep /dev/shm

Step 5: Secure the /proc filesystem

/proc exposes kernel and process information. Attackers can use it to gather system details. You can restrict access by adding the hidepid option. This hides other users’ process information from non-root users.

In /etc/fstab, add or modify the /proc entry.

proc /proc proc defaults,hidepid=2 0 0

The hidepid=2 option means non-root users can only see their own processes. They won’t see processes owned by other users or root. For more detail on proc filesystem options, see the official Linux kernel /proc documentation.

Remount /proc to apply the change immediately.

sudo mount -o remount /proc

Step 6: Bind-mount /tmp to /var/tmp for consistency

/var/tmp is another writable directory. It should also inherit the same restrictions. You can bind-mount it to /tmp so it uses the same secure options.

Add this line to /etc/fstab.

/tmp /var/tmp none bind 0 0

Then remount it.

sudo mount -o remount /var/tmp

Step 7: Reboot and verify all settings persist

Reboot your server to confirm all mount options survive a restart.

sudo reboot

After the server comes back online, run this to verify everything is correctly applied.

mount | grep -E '/tmp|/dev/shm|/proc'

Check the output carefully. You should see your noexec, nosuid, nodev, and hidepid options listed for the correct filesystems.

Troubleshooting Common Issues When Hardening Linux Filesystem Mounts

Problem: Server won’t boot after editing /etc/fstab

This is the most serious risk. If you made a syntax error in /etc/fstab, the server may fail to boot. Use your hosting provider’s rescue console or boot into recovery mode. Then restore your backup.

sudo cp /etc/fstab.bak /etc/fstab

Problem: Applications break after applying noexec to /tmp

Some applications write and execute scripts in /tmp. Common offenders include certain PHP-based apps and some package installers. If an app breaks, check its logs first. You may need to configure that app to use a different temporary directory. For example, you can point PHP’s upload_tmp_dir to a separate directory that allows execution.

Problem: hidepid=2 breaks system services

Some services like gdm or certain monitoring tools need to read process information from /proc. If a service breaks, you can add specific users to the proc group and use hidepid=2,gid=proc instead. Members of that group will still have full visibility.

proc /proc proc defaults,hidepid=2,gid=proc 0 0

Then add the service user to the proc group.

sudo usermod -aG proc www-data

Problem: /dev/shm noexec breaks shared memory applications

Some applications use /dev/shm for inter-process communication and may need execution rights. PostgreSQL is one example. Check your application documentation before applying noexec to /dev/shm. The Ubuntu Server documentation is a good resource for understanding service-specific requirements.

Conclusion

You now know how to harden Linux server security by securing filesystem mount options for /tmp, /dev/shm, and /proc on Ubuntu Server. These changes are simple but genuinely effective. They block a wide range of common attack techniques without disrupting normal server operation. You’ve applied noexec, nosuid, and nodev to writable directories. You’ve also restricted process visibility with hidepid. These are foundational steps in any server hardening checklist.

From here, consider exploring additional hardening steps. You can disable unused kernel modules, configure a firewall with ufw, or set up automatic security updates. Each layer you add makes your server significantly harder to compromise. Start with what you’ve done here and build from it.

Similar Posts