(re-)mount home [and other?] with noexec (and nosuid [among other useful mount options]) for better security?

This needs a revision.

systemd unit file to remount /home /tmp /dev/shm /run with nosuid,nodev

1 Like