RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel Protections
Kyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing, Ruoyu Wang, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao
Abstract
Leveraging a control flow hijacking primitive (CFHP) to gain root privileges is critical to attackers striving to exploit Linux kernel vulnerabilities. Such attack has become increasingly elusive as security researchers propose capable kernel security mitigations, leading to the development of complex (and, as a trade-off, brittle and unreliable) attack techniques to regain it. In this paper, we obviate the need for complexity by proposing RetSpill, a powerful yet elegant exploitation technique that employs user space data already present on the kernel stack for privilege escalation. RetSpill exploits the common practice of temporarily storing data on the kernel stack, such as when preserving user space register values during a switch from the user space to the kernel space. We perform a systematic study and identify four common practices that spill user space data to the kernel stack. Although this practice is perfectly within the kernel's security specification, it introduces a new exploitation path when paired with a control flow hijacking (CFH) vulnerability, enabling RetSpill to turn such vulnerabilities directly into privilege escalation reliably. Moreover, RetSpill can bypass many defenses currently deployed in the Linux kernels. To demonstrate the severity of this problem, we collected 22 real-world kernel vulnerabilities and built a semi-automated tool that abuses intentionally-stored, on-stack user space data for kernel exploitation in a semi-automated fashion. Our tool generated end-to-end privilege escalation exploits for 20 out of 22 CFH vulnerabilities. Finally, we propose a new mechanism to defend against the attack. CCS CONCEPTS • Security and privacy → Operating systems security; Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers16
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber et al.USENIX Security 2024 · 16 citations
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu et al.NDSS 2026 · 3 citations
- ropbot: Reimaging Code Reuse Attack SynthesisKyle Zeng, Moritz Schloegel, Christopher Salls, Adam Doupé et al.NDSS 2026 · 1 citation
- DirtyFree: Simplified Data-Oriented Programming in the Linux KernelYoochan Lee, Hyuk Kwon, Thorsten HolzNDSS 2026 · 1 citation
- Tide: An Efficient Kernel-level Isolation Execution Environment on AArch64 via Dynamically Adjusting Output Address SizeShiyang Zhang, Chenggang Wu, Chengxuan Hou, Jinglin Lv et al.CCS 2025
Builds on18
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing et al.USENIX Security 2018 · 124 citations
- UniSan: Proactive Kernel Memory Initialization to Eliminate Data LeakagesKangjie Lu, Chengyu Song, Taesoo Kim, Wenke LeeCCS 2016 · 81 citations
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
Related papers
- DirtyCred: Escalating Privilege in Linux KernelZhenpeng Lin, Yuhang Wu, Xinyu XingCCS 2022 · 30 citations
- System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the SystemJennifer Miller, Manas Ghandat, Kyle Zeng, Hongkai Chen et al.USENIX Security 2025
- EPF: Evil Packet FilterDi Jin, Vaggelis Atlidakis, Vasileios P. KemerlisUSENIX ATC 2023 · 14 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
- ExpRace: Exploiting Kernel Races through Raising InterruptsYoochan Lee, Changwoo Min, Byoungyoung LeeUSENIX Security 2021 · 40 citations
