SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive Perspective
Yinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu, Yuan Li
Abstract
—Despite extensive efforts to harden the Linux ker-nel—the foundation powering numerous widely-used distributions (e.g., Ubuntu, Debian, Fedora)—it continues to face persistent and sophisticated memory safety vulnerabilities. In this study, we introduce a novel systematic framework that de-composes kernel exploitation into three distinct phases from an attacker’s perspective. Through comprehensive analysis of 121 publicly documented exploits since 2015, we identify and categorize 64 recurrent attack vectors. Leveraging this structured approach, we perform an in-depth evaluation of 51 existing kernel defense mechanisms, clearly mapping their coverage, limitations, redundancies, and interdependencies. Our results reveal significant protection gaps: 23 attack vectors remain entirely unprotected, and 31 existing defenses are bypassable or obsolete. Additionally, we uncover notable discrepancies between theoretical effectiveness and practical deployment across popular downstream distributions, highlighting 4 underutilized hardening measures and misconfigurations in four major distributions. By illuminating these critical gaps and offering actionable insights, our work guides both kernel developers and security practitioners in enhancing defensive strategies and refining future security designs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6c8a2f7e-dbbc-44c9-a87a-72f54178d08dBuilds on11
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
- Unleashing Use-Before-Initialization Vulnerabilities in the Linux Kernel Using Targeted Stack SprayingKangjie Lu, Marie-Therese Walter, David Pfaff, Stefan Nümberger et al.NDSS 2017 · 58 citations
- Gollum: Modular and Greybox Exploit Generation for Heap Overflows in InterpretersSean Heelan, Tom Melham, Daniel KroeningCCS 2019 · 50 citations
- CONFIRM: Evaluating Compatibility and Relevance of Control-flow Integrity Protections for Modern SoftwareXiaoyang Xu, Masoud Ghaffarinia, Wenhao Wang, Kevin W. Hamlen et al.USENIX Security 2019 · 49 citations
Related papers
- Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android KernelsLukas Maar, Florian Draschbacher, Lukas Lamster, Stefan MangardUSENIX Security 2024 · 5 citations
- Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata FieldsHao Zhang, Jian Liu, Jie Lu, Shaomin Chen et al.CCS 2025
- Building Embedded Systems Like It's 1996Ruotong Yu, Francesca Del Nin, Yuchen Zhang, Shan Huang et al.NDSS 2022
- Fence2Pwn: KFENCE-Enabled Kernel Exploitation Bypassing Slab Hardening and Memory TaggingErnesto Martínez García, Lukas Maar, Martin Unterguggenberger, Stefan MangardUSENIX Security 2026
- When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel LeaksLukas Maar, Lukas Giner, Daniel Gruss, Stefan MangardUSENIX Security 2025
