DirtyFree: Simplified Data-Oriented Programming in the Linux Kernel
Yoochan Lee, Hyuk Kwon, Thorsten Holz
Abstract
—With the advent of Kernel Control-Flow Integrity (KCFI), Data-Oriented Programming (DOP) has emerged as an essential alternative to traditional control-flow hijacking techniques such as Return-Oriented Programming (ROP). Unlike control-flow attacks, DOP manipulates kernel data-flow to achieve privilege escalation without violating control-flow integrity. However, traditional DOP attacks remain complex and exhibit limited practicality due to their multistage nature, typically requiring heap address leakage, arbitrary address read, and arbitrary address write capabilities. Each stage imposes strict constraints on the selection and usage of kernel objects. To address these limitations, we introduce D IRTY F REE , a systematic exploitation method that leverages the arbitrary free primitive. This primitive enables the forced deallocation of attacker-controlled kernel objects, significantly reducing ex-ploitability requirements and simplifying the overall exploitation process. D IRTY F REE provides a systematic method for identifying suitable arbitrary free objects across diverse kernel caches and presents a structured exploitation strategy targeting security-critical objects such as cred . Through extensive evaluation, we successfully identified 14 arbitrary free objects covering most kernel caches, demonstrating D IRTY F REE ’s practical effectiveness by successfully exploiting 24 real-world kernel vulnerabilities. Additionally, we propose and implement two mitigation techniques designed to mitigate D IRTY F REE , effectively preventing exploitation while incurring negligible performance overhead (i.e., 0.28% and -0.55%, respectively).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a0c7e0ed-3523-49ae-afa1-e6885c5b4009Cited by top-tier papers2
- Discovering, characterizing and exploiting controllable-copy objects for kernel data-only attacks with CopyKatJakob Koschel, Andrea Mambretti, Alessandro Sorniotti, Pietro Moretto et al.USENIX Security 2026
- Fence2Pwn: KFENCE-Enabled Kernel Exploitation Bypassing Slab Hardening and Memory TaggingErnesto Martínez García, Lukas Maar, Martin Unterguggenberger, Stefan MangardUSENIX Security 2026
Builds on26
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Hacking in Darkness: Return-oriented Programming against Secure EnclavesJae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak et al.USENIX Security 2017 · 191 citations
- HDFI: Hardware-Assisted Data-Flow IsolationChengyu Song, Hyungon Moon, Monjur Alam, Insu Yun et al.S&P 2016 · 146 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing et al.USENIX Security 2018 · 124 citations
Related papers
- DirtyCred: Escalating Privilege in Linux KernelZhenpeng Lin, Yuhang Wu, Xinyu XingCCS 2022 · 30 citations
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 8 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
- Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CETMarcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian RossowS&P 2026
- RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel ProtectionsKyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing et al.CCS 2023 · 9 citations
