from small one page howto to huge articles all in one place

search text in:

Which screen resolution do you use?

poll results

Last additions:
using iotop to find disk usage hogs

using iotop to find disk usage hogs






average rating: 1.7 (82 votes) (1=very good 6=terrible)

May 25th. 2007:




why adblockers are bad

Workaround and fixes for the current Core Dump Handling vulnerability affected kernels

Workaround and fixes for the current Core Dump Handling vulnerability affected kernels






average rating: 1.3 (27 votes) (1=very good 6=terrible)

April, 26th. 2006:

You are here: manpages


Section: Documentation for elfix (1)
Updated: 2014-11-03
Index Return to Main Contents


paxctl-ng - get, set or create either PT_PAX or XATTR_PAX flags  


paxctl-ng -PpEeMmRrXxSs|-Z|-z [-L|-l] [-v] ELF

paxctl-ng -C|-c|-d [-v] ELF

paxctl-ng -F|-f [-v] ELF

paxctl-ng -L|-l

paxctl-ng [-h]  


paxctl-ng is used to get, set or create the PaX flags on ELF executables which determine the memory restrictions on process(es) spawned from them when run under a PaX enabled kernel. paxctl-ng manages two types of markings, either the older style PT_PAX markings which put the flags in an ELF program header named PAX_FLAGS, or the newer style XATTR_PAX markings which put the flags in an extended attribute field named user.pax.flags on the filesystem. Whenever possible, paxctl-ng will try to set both PT_PAX and XATTR_PAX to the same flags.

There are drawbacks to both PT_PAX and XATTR_PAX markings. PT_PAX will not work on ELF binaries which do not already have a PAX_FLAGS program header. Unlike the original tool, paxctl, which could be instructed to try to add this header or convert a GNU_STACK header, paxctl-ng does not edit the ELF in any way, beyond setting the PaX flags if and only if the PAX_FLAGS program header already exists. Some ELF binaries break when they are edited. Since, paxctl-ng will never to so, it is usually safe to run it on such binaries.

Alternatively, XATTR_PAX requires filesystems that support extended attributes. Most modern filesystems do so, but not all. Furthermore, one must be careful when moving ELF objects to ensure that the target filesystem or archive supports extended attributes, otherwise they are lost, unlike PT_PAX markings which are carried within the binary itself.

paxctl-ng is opportunistic without taking control away from the user. If both a PAX_FLAGS program header and a user.pax.flags extended attribute field exist, then both will be equally updated when the user modifies flags; unless the -L or -l flags are given, in which case the markings are limiting to just PT_PAX or XATTR_PAX, respectively. If only one marking is possible, then only that marking will be updated. Under no circumstances will paxctl-ng create a PAX_FLAGS program header as paxctl does. It will only attempt to create an extended attribute field if it is instructed to do so with the -C or -c flags, and it will attempt to synchronize the PT_PAX and XATTR_PAX markings if given the -F or -f flags. Note that when copying PT_PAX to XATTR_PAX with the -F flag, if the user.pax.flags extended attribute field does not exist, paxctl-ng will create it as if given either the -C or -c flags. Finally, if the user wishes, he can remove the extended attribute field by running paxctl-ng with the -d flag.  


-P or -p Enable or disable PAGEEXEC
-S or -s Enable or disable SEGMEXEC
-M or -m Enable or disable MPROTECT
-E or -e Enable or disable EMUTRAMP
-R or -r Enable or disable RANDMMAP
-X or -x Enable or disable RANDEXEC
If both enabling and disabling flags are set for one item, eg. -Pp for PAGEEXEC, then the default setting '-' is used.
-Z Set most secure settings (PSMeRx).
-z Set default setting (------).
-C Create XATTR_PAX markings with the most secure PaX settings.
-c Create XATTR_PAX markings with the default PaX settings.
-d Delete XATTR_PAX field, user.pax.flags.
-F Copy PT_PAX flags to XATTR_PAX, if possible.
-f Copy XATTR_PAX flags to PT_PAX, if possible.
-L When given with other flags, only set PT_PAX flags, if possible. When given alone, return EXIT_SUCCESS if PT_PAX is supported, else return EXIT_FAILURE.
-l When given with other flags, only set XATTR_PAX flags, if possible. When given alone, return EXIT_SUCCESS if XATTR_PAX is supported, else return EXIT_FAILURE.
-v View the flags
-h Print out a short help message and exit.



Please report bugs at  


scanelf(1), dumpelf(1), paxctl(1), pspax(1), fix-gnustack(1).  


Anthony G. Basile <>




Please read "Why adblockers are bad".

Other free services
Shorten long
URLs to short
links like
Reverse DNS lookup
Find out which hostname(s)
resolve to a
given IP or other hostnames for the server
rdf newsfeed | rss newsfeed | Atom newsfeed
- Powered by LeopardCMS - Running on Gentoo -
Copyright 2004-2013 Sascha Nitsch Unternehmensberatung UG(haftungsbeschränkt)
Valid XHTML1.1 : Valid CSS : buttonmaker
- Level Triple-A Conformance to Web Content Accessibility Guidelines 1.0 -
- Copyright and legal notices -
Time to create this page: 3.5 ms