Characterizing, exploiting, and detecting DMA code injection vulnerabilities in the presence of an IOMMU
Alex Markuze, Shay Vargaftik, Gil Kupfer, Boris Pismenny, Nadav Amit, Adam Morrison, Dan Tsafrir
Abstract
Direct memory access (DMA) renders a system vulnerable to DMA attacks, in which I/O devices access memory regions not intended for their use. Hardware input-output memory management units (IOMMU) can be used to provide protection. However, an IOMMU cannot prevent all DMA attacks because it only restricts DMA at page-level granularity, leading to sub-page vulnerabilities.
Current DMA attacks rely on simple situations in which write access to a kernel pointer is obtained due to sub-page vulnerabilities and all other attack ingredients are available and reside on the same page. We show that DMA vulnerabilities are a deep-rooted issue and it is often the kernel design that enables complex and multistage DMA attacks. This work presents a structured top-down approach to characterize, exploit, and detect them.
To this end, we first categorize sub-page vulnerabilities into four types, providing insight into the structure of DMA vulnerabilities. We then identify a set of three vulnerability attributes that are sufficient to execute code injection attacks.
We built analysis tools that detect these sub-page vulnerabilities and analyze the Linux kernel. We found that 72% of the device drivers expose callback pointers, which may be overwritten by a device to hijack the kernel control flow.
Aided by our tools' output, we demonstrate novel code injection attacks on the Linux kernel; we refer to these as compound attacks. All previously reported attacks are singlestep, with the vulnerability attributes present in a single page. In compound attacks, the vulnerability attributes are initially incomplete. However, we demonstrate that they can be obtained by carefully exploiting standard OS behavior.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 225e37c4-3e33-4b4c-a5f4-70ce0c467d28Cited by top-tier papers8
- sIOPMP: Scalable and Efficient I/O Protection for TEEsErhu Feng, Dahu Feng, Dong Du, Yubin Xia et al.ASPLOS 2024 · 10 citations
- DMAAUTH: A Lightweight Pointer Integrity-based Secure Architecture to Defeat DMA AttacksXingkai Wang, Wenbo Shen, Yujie Bu, Jinmeng Zhou et al.USENIX Security 2024 · 2 citations
- GHost in the Shell: A GPU-to-Host Memory Attack and its MitigationSihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee et al.S&P 2026 · 2 citations
- Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeShiyang Zhang, Chenggang Wu, Chengxuan Hou, Jinglin Lv et al.CCS 2025
- Dynamic Detection of Vulnerable DMA Race ConditionsBrian Johannesmeyer, Raphael Isemann, Cristiano Giuffrida, Herbert BosCCS 2025
Builds on3
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin et al.S&P 2016 · 242 citations
- Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy PeripheralsA. Theodore Markettos, Colin Rothwell, Brett F. Gutstein, Allison Pearce et al.NDSS 2019 · 97 citations
- Defending against Malicious Peripherals with CinchSebastian Angel, Riad S. Wahby, Max Howald, Joshua B. Leners et al.USENIX Security 2016 · 44 citations
Related papers
- Static Detection of Unsafe DMA Accesses in Device DriversJia-Ju Bai, Tuo Li, Kangjie Lu, Shi-Min HuUSENIX Security 2021 · 28 citations
- GDMA: Fully Automated DMA Rehosting via Iterative Type OverlaysTobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner et al.USENIX Security 2025
- DevIOus: Device-Driven Side-Channel Attacks on the IOMMUTaehun Kim, Hyeongjin Park, Seokmin Lee, Seunghee Shin et al.S&P 2023
- Insvdf: Interface-State-Aware Virtual Device FuzzingZexiang Zhang, Gaoning Pan, Ruipeng Wang, Yiming Tao et al.ICSE 2025 · 2 citations
- DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisAlejandro Mera, Bo Feng, Long Lu, Engin KirdaS&P 2021 · 81 citations
