USENIX Security2026Top-tier venue
PICASSO: Scaling CHERI Use-After-Free Protection to Millions of Allocations using Colored Capabilities
Merve Gülmez, Ruben Sturm, Hossam ElAtali, Håkan Englund, Jonathan Woodruff, N. Asokan, Thomas Nyman
Abstract
While the CHERI instruction-set architecture extensions for capabilities enable strong spatial memory safety, CHERI lacks built-in temporal safety, particularly for heap allocations. Prior attempts to augment CHERI with temporal safety fall short in terms of scalability, memory overhead, and incomplete security guarantees due to periodical sweeps of the system's memory to individually revoke stale capabilities. We address these limitations by introducing colored capabilities that add a controlled form of indirection to CHERI's capability model. This enables provenance tracking of capabilities to their respective allocations via a hardware-managed provenance-validity table, allowing bulk retraction of dangling pointers without needing to quarantine freed memory. Colored capabilities significantly reduce the frequency of capability revocation sweeps while improving security. We realize colored capabilities in PICASSO, an extension of the CHERI-RISC-V architecture on a speculative out-of-order FPGA softcore (CHERI-Toooba). We also integrate colored-capability support into the CheriBSD OS and CHERI-enabled Clang/LLVM toolchain. Our evaluation shows effective mitigation of use-after-free and double-free bugs across all heap-based temporal memory-safety vulnerabilities in NIST Juliet test cases, real-world CVEs, only a small performance overhead on SPEC CPU benchmarks (≈ 5% g.m.), less latency, and more consistent performance in long-running SQLite, PostgreSQL, and gRPC workloads compared to prior work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a8086172-e3cf-495c-bf40-e247a7e66b66Cited by top-tier papers1
Ask how each one uses itBuilds on19
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 77 citations
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
- PTAuth: Temporal Memory Safety via Robust Points-to AuthenticationReza Mirzazade Farkhani, Mansour Ahmadi, Long LuUSENIX Security 2021 · 67 citations
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 63 citations
Related papers
- Cornucopia Reloaded: Load Barriers for CHERI Heap Temporal SafetyNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Jessica Clarke et al.ASPLOS 2024 · 16 citations
- Mon CHERI: Mitigating Uninitialized Memory Access with Conditional CapabilitiesMerve Gülmez, Håkan Englund, Jan Tobias Mühlberg, Thomas NymanS&P 2025
- BLACKOUT: Data-Oblivious Computation with Blinded CapabilitiesHossam ElAtali, Merve Gülmez, Thomas Nyman, N. AsokanCCS 2025
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson et al.USENIX Security 2023
- CapOpt: Capability-Aware Superoptimization for Secure and Provably Faster CodeXiaoyang Sun, Dejice Jacob, Huanting Wang, Jeremy Singer et al.OOPSLA 2026
