Details
The noexec mount option specifies that the filesystem cannot contain executable binaries.
*Rationale*
Since the /tmp filesystem is only intended for temporary file storage, set this option to
ensure that users cannot run executable binaries from /tmp.
Solution
Edit the /etc/fstab file and add noexec to the fourth field (mounting options). See the
fstab(5) manual page for more information.# mount -o remount,noexec /tmp
Supportive Information
The following resource is also helpful.
This control applies to the following type of system Unix.