USENIX Security2026Top-tier venue
Fence2Pwn: KFENCE-Enabled Kernel Exploitation Bypassing Slab Hardening and Memory Tagging
Ernesto Martínez García, Lukas Maar, Martin Unterguggenberger, Stefan Mangard
Abstract
While the Linux kernel remains a prime target due to its privileged execution model, exploitation has become substantially more difficult in recent years. Kernel hardening efforts have increasingly focused on the slab allocator, aiming to mitigate entire vulnerability classes (e.g., via memory tagging) or disrupt exploit techniques (e.g., via heap object segregation). However, it remains unclear whether these protections are consistently enforced across all allocation paths. In this paper, we find that one allocation path is excluded from all state-of-the-art slab defenses: the path used for KFENCE allocations. KFENCE is designed as a low-overhead sampling-based memory-safety error detector for production kernels. It is enabled by default and active in billions of systems including on Android, Red Hat Enterprise Linux, and most Linux distributions. We show that it unintentionally enables a new exploit technique, Fence2Pwn. Concretely, Fence2Pwn leverages several KFENCE-specific behaviors. Three are particularly notable: (i) using a timing side channel, we detect when the kernel falls back to KFENCE allocations; (ii) KFENCE allocations are served by KFENCE-managed caches rather than size- and type-segregated slab caches, enabling bypass of heap segregation; and (iii) KFENCE allocations are untagged, enabling bypass of memory tagging. We evaluate Fence2Pwn by profiling our timing side channel, KFENCE's object slot dynamics as well as different environments and noise floors. Finally, we demonstrate that Fence2Pwn exploits this slab-defense gap: Fence2Pwn uses KFENCE to exploit an existing UAF-based memory-reuse vulnerability, which allows it to overlay security-relevant objects of different types and sizes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on10
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- DirtyCred: Escalating Privilege in Linux KernelZhenpeng Lin, Yuhang Wu, Xinyu XingCCS 2022 · 30 citations
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber et al.USENIX Security 2024 · 16 citations
- RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel ProtectionsKyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing et al.CCS 2023 · 9 citations
- DirtyFree: Simplified Data-Oriented Programming in the Linux KernelYoochan Lee, Hyuk Kwon, Thorsten HolzNDSS 2026 · 1 citation
Related papers
- Pspray: Timing Side-Channel based Linux Kernel Heap Exploitation TechniqueYoochan Lee, Jinhan Kwak, Junesoo Kang, Yuseok Jeon et al.USENIX Security 2023
- When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel LeaksLukas Maar, Lukas Giner, Daniel Gruss, Stefan MangardUSENIX Security 2025
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- SeaK: Rethinking the Design of a Secure Allocator for OS KernelZicheng Wang, Yicheng Guang, Yueqi Chen, Zhenpeng Lin et al.USENIX Security 2024 · 1 citation
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee et al.S&P 2026
