In addition, making /tmp its own file system allows an administrator to set the noexec option on the mount, making /tmp
useless for an attacker to install executable code. It would also prevent an attacker from establishing a hardlink to a system setuid program and wait for it to be updated