Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux Kernel
Brian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida
Abstract
—Due to the high cost of serializing instructions to mitigate Spectre-like attacks on mispredicted conditional branches (Spectre-PHT), developers of critical software such as the Linux kernel selectively apply such mitigations with annotations to code paths they assume to be dangerous under speculative execution. The approach leads to incomplete protection as it applies mitigations only to easy-to-spot gadgets. Still, until now, this was sufficient, because existing gadget scanners (and kernel developers) are pattern-driven: they look for known exploit signatures and cannot detect more generic gadgets. In this paper, we abandon pattern scanning for an approach that models the essential steps used in speculative execution attacks, allowing us to find more generic gadgets—well beyond the reach of existing scanners. In particular, we present K ASPER , a speculative execution gadget scanner that uses taint analysis policies to model an attacker capable of exploiting arbitrary software/hardware vulnerabilities on a transient path to control data (e.g., through memory massaging or LVI), access secrets (e.g., through out-of-bounds or use-after-free accesses), and leak these secrets (e.g., through cache-based, MDS-based, or port contention-based covert channels). Finally, where existing solutions target user programs, K ASPER finds gadgets in the kernel, a higher-value attack target, but also more complicated to analyze. Even though the kernel is heavily hardened against transient execution attacks, K ASPER finds 1379 gadgets that are not yet mitigated. We confirm our findings by demonstrating an end-to-end proof-of-concept exploit for one of the gadgets found by K ASPER .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 32 citations
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 19 citations
- Practical Data-Only Attack GenerationBrian Johannesmeyer, Asia Slowinska, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 16 citations
- Leaky Address Masking: Exploiting Unmasked Spectre Gadgets with Noncanonical Address TranslationMathé Hertogh, Sander Wiebing, Cristiano GiuffridaS&P 2024 · 15 citations
- ShadowLoad: Injecting State into Hardware PrefetchersLorenz Hetterich, Fabian Thomas, Lukas Gerlach, Ruiyi Zhang et al.ASPLOS 2025 · 9 citations
Builds on21
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- SpecTaint: Speculative Taint Analysis for Discovering Spectre GadgetsZhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan et al.NDSS 2021
- Perspective: A Principled Framework for Pliable and Secure Speculation in Operating SystemsTae Hoon Kim, David Rudo, Kaiyang Zhao, Zirui Neil Zhao et al.ISCA 2024 · 6 citations
- Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order ProcessorsLukas Gerlach, Marton Bognar, Daniel Weber, Michael Schwarz et al.USENIX Security 2026
- GhostRace: Exploiting and Mitigating Speculative Race ConditionsHany Ragab, Andrea Mambretti, Anil Kurmus, Cristiano GiuffridaUSENIX Security 2024 · 10 citations
- An Analysis of Speculative Type Confusion Vulnerabilities in the WildOfek Kirzner, Adam MorrisonUSENIX Security 2021 · 40 citations
