USENIX Security2024Top-tier venue
SCAVY: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation
Erin Avllazagaj, Yonghwi Kwon, Tudor Dumitras
Abstract
Kernel privilege-escalation exploits typically leverage memory-corruption vulnerabilities to overwrite particular memory locations. These memory corruption targets play a critical role in the exploits, as they determine which privileged resources (e.g. files, memory, and operations) the adversary may access and what privileges (e.g. read, write, and unrestricted) they may gain. While prior research has made important advances in discovering vulnerabilities, and in automating their exploitation, it relies on the few memory corruption targets that have been discovered manually so far. We propose SCAVY, a framework that automatically discovers memory corruption targets for privilege escalation in the Linux kernel. The key insight behind SCAVY is to extend the search beyond the kernel data structures that include function pointers, or pointers to such structures, and that were studied in prior work while accounting for approximately one tenth of the kernel structures. Additionally, the search is bug-type agnostic, as it considers any memory corruption capability. To this end, we develop novel and scalable techniques that combine fuzzing and differential analysis to automatically explore and detect privilege escalation by comparing the accessibility of resources between executions with and without corruption. This allows SCAVY to determine that corrupting a certain field puts the system in an exploitable state, independently of the vulnerability exploited. SCAVY found 955 PoC, from which we identify 17 fields belonging to 12 structures -when corrupted they have shown to reach a privilege escalation state. We further develop 6 exploits for 5 vulnerabilities. Our findings show that memory corruption targets can change the security implications of vulnerabilities, urging researchers to proactively discover memory corruption targets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 1 citation
- Optimizing Input Minimization in Kernel FuzzingHui Guo, Hao Sun, Shan Huang, Ting Su et al.USENIX ATC 2025 · 1 citation
- Discovering, characterizing and exploiting controllable-copy objects for kernel data-only attacks with CopyKatJakob Koschel, Andrea Mambretti, Alessandro Sorniotti, Pietro Moretto et al.USENIX Security 2026
- System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the SystemJennifer Miller, Manas Ghandat, Kyle Zeng, Hongkai Chen et al.USENIX Security 2025
- Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain AttacksGaoning Pan, Yiming Tao, Qinying Wang, Chunming Wu et al.NDSS 2026
Builds on15
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 139 citations
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing et al.USENIX Security 2018 · 124 citations
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
Related papers
- BridgeRouter: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux KernelDongchen Xie, Dongnan He, Wei You, Jianjun Huang et al.S&P 2025
- KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write VulnerabilitiesWeiteng Chen, Xiaochen Zou, Guoren Li, Zhiyun QianUSENIX Security 2020
- SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept ExploitsWei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang et al.CCS 2017 · 148 citations
- K-Miner: Uncovering Memory Corruption in LinuxDavid Gens, Simon Schmitt, Lucas Davi, Ahmad-Reza SadeghiNDSS 2018 · 58 citations
- AlphaEXP: An Expert System for Identifying Security-Sensitive Kernel ObjectsRuipeng Wang, Kaixiang Chen, Chao Zhang, Zulie Pan et al.USENIX Security 2023
