USENIX Security2026Top-tier venue
DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free Vulnerabilities
Juhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung Lee
Abstract
Modern kernels depend on the integrity of page tables to enforce advanced security measures. Although these defenses have effectively mitigated various attacks including memory corruption, adversaries have shifted their focus to compromise the page table itself to bypass existing protections. Such threats are exacerbated by the rise of heterogeneous address translation domains including separate CPU, GPU, and IOMMU page tables, which impose heavy demands on synchronization and coherence management. When a virtual address remains mapped to a physical page that has already been freed or reallocated, attackers can exploit this to access arbitrary physical memory. We call this physical-page use-after-free, distinct from traditional heap use-after-free that operates on virtual addresses. In this paper, we present DMGuard, the first runtime mitigation that comprehensively addresses physical-page use-after-free vulnerabilities across diverse translation domains. DMGuard leverages a lightweight, lockless mechanism to manage a state machine of physical pages to ensure no dangling mappings exist in the page tables. Evaluation of DMGuard on Android devices demonstrates that it effectively blocks all known physical-page use-after-free vulnerabilities with negligible performance overheads, demonstrating the practicality and effectiveness against emerging attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext afc268b7-30b6-4a9b-9485-c2d31854878bBuilds on16
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
- SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory IsolationZhe Wang, Chenggang Wu, Mengyao Xie, Yinqian Zhang et al.S&P 2020 · 37 citations
- Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code PagesSeunghun Han, Seong-Joong Kim, Wook Shin, Byung Joon Kim et al.USENIX Security 2024 · 9 citations
- BUDAlloc: Defeating Use-After-Free Bugs by Decoupling Virtual Address Management from KernelJunho Ahn, Jaehyeon Lee, Kanghyuk Lee, Wooseok Gwak et al.USENIX Security 2024 · 6 citations
Related papers
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang et al.USENIX Security 2021 · 53 citations
- GHost in the Shell: A GPU-to-Host Memory Attack and its MitigationSihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee et al.S&P 2026 · 2 citations
- PhantomMap: GPU-Assisted Kernel ExploitationJiayi Hu, Qi Tang, Xingkai Wang, Jinmeng Zhou et al.NDSS 2026
- ViK: practical mitigation of temporal memory safety violations through object ID inspectionHaehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao et al.ASPLOS 2022 · 13 citations
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
