Adelie: continuous address space layout re-randomization for Linux drivers
Ruslan Nikolaev, Hassan Nadeem, Cathlyn Stone, Binoy Ravindran
Abstract
While address space layout randomization (ASLR) has been extensively studied for user-space programs, the corresponding OS kernel's KASLR support remains very limited, making the kernel vulnerable to just-in-time (JIT) return-oriented programming (ROP) attacks. Furthermore, commodity OSs such as Linux restrict their KASLR range to 32 bits due to architectural constraints (e.g., x86-64 only supports 32-bit immediate operands for most instructions), which makes them vulnerable to even unsophisticated brute-force ROP attacks due to low entropy. Most in-kernel pointers remain static, exacerbating the problem when pointers are leaked.
Adelie, our kernel defense mechanism, overcomes KASLR limitations, increases KASLR entropy, and makes successful ROP attacks on the Linux kernel much harder to achieve. First, Adelie enables the position-independent code (PIC) model so that the kernel and its modules can be placed anywhere in the 64-bit virtual address space, at any distance apart from each other. Second, Adelie implements stack re-randomization and address encryption on modules. Finally, Adelie enables efficient continuous KASLR for modules by using the PIC model to make it (almost) impossible to inject ROP gadgets through these modules regardless of gadget's origin.
Since device drivers (typically compiled as modules) are often developed by third parties and are typically less tested than core OS parts, they are also often more vulnerable. By fully re-randomizing device drivers, the last two contributions together prevent most JIT ROP attacks since vulnerable modules are very likely to be a starting point of an attack. Furthermore, some OS instances in virtualized environments are specifically designated to run device drivers, where drivers are the primary target of JIT ROP attacks. Using a GCC plugin that we developed, we automatically modify different kinds of kernel modules. Since the prior art tackles only user-space programs, we solve many challenges unique to * The U.S. Government is authorized to reproduce and distribute reprints for Governmental purposes notwithstanding any copyright annotation thereon.
† Most of the work was done while the author worked at Virginia Tech.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3d5bbec8-05c4-4c90-b84f-51b145702edcCited by top-tier papers3
- Kite: lightweight critical service domainsA. K. M. Fazla Mehrab, Ruslan Nikolaev, Binoy RavindranEuroSys 2022 · 8 citations
- Demystifying and Exploiting ASLR on NVIDIA GPUsRuofan Zhu, Ganhao Chen, Wenbo Shen, Lyuye Zhang et al.S&P 2026 · 2 citations
- Oreo: Protecting ASLR Against Microarchitectural AttacksShixin Song, Joseph Zhang, Mengjia YanNDSS 2025
Builds on4
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Hacking in Darkness: Return-oriented Programming against Secure EnclavesJae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak et al.USENIX Security 2017 · 191 citations
- Egalito: Layout-Agnostic Binary RecompilationDavid Williams-King, Hidenori Kobayashi, Kent Williams-King, Graham Patterson et al.ASPLOS 2020 · 68 citations
- Snapshot-free, transparent, and robust memory reclamation for lock-free data structuresRuslan Nikolaev, Binoy RavindranPLDI 2021 · 18 citations
Related papers
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi et al.NDSS 2016 · 90 citations
- The Illusion of Randomness: An Empirical Analysis of Address Space Layout Randomization ImplementationsLorenzo Binosi, Gregorio Barzasi, Michele Carminati, Stefano Zanero et al.CCS 2024 · 4 citations
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
- A Systematic Study of Elastic Objects in Kernel ExploitationYueqi Chen, Zhenpeng Lin, Xinyu XingCCS 2020 · 35 citations
