USENIX Security2023Top-tier venue
Uncontained: Uncovering Container Confusion in the Linux Kernel
Jakob Koschel, Pietro Borrello, Daniele Cono D'Elia, Herbert Bos, Cristiano Giuffrida
Abstract
Type confusion bugs are a common source of security problems whenever software makes use of type hierarchies, as an inadvertent downcast to an incompatible type is hard to detect at compile time and easily leads to memory corruption at runtime. Where existing research mostly studies type confusion in the context of object-oriented languages such as C++, we analyze how similar bugs affect complex C projects such as the Linux kernel. In particular, structure embedding emulates type inheritance between typed structures. Downcasting in such cases consists of determining the containing structure from the embedded one, and, like its C++ counterpart, may well lead to bad casting to an incompatible type. In this paper, we present uncontained, a systematic, two-pronged solution to discover type confusion vulnerabilities resulting from incorrect downcasting on structure embeddings—which we call container confusion. First, we design a novel sanitizer to dynamically detect such issues and evaluate it on the Linux kernel, where we find as many as 11 container confusion bugs. Using the patterns in the bugs detected by the sanitizer, we then develop a static analyzer to find similar bugs in code that dynamic analysis fails to reach and detect another 78 bugs. We reported and proposed patches for all the bugs (with 102 patches already merged and 6 CVEs assigned), cooperating with the Linux kernel maintainers towards safer design choices for container manipulation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b27c307d-9599-432a-9324-a8fec3269bc9Cited by top-tier papers5
- GlobalConfusion: TrustZone Trusted Application 0-Days by DesignMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 4 citations
- On Kernel's Safety in the Spectre Era (And KASLR is Formally Dead)Davide Davoli, Martin Avanzini, Tamara RezkCCS 2024 · 2 citations
- TIPS: Tracking Integer-Pointer Value Flows for C++ Member Function PointersChangwei Zou, Dongjie He, Yulei Sui, Jingling XueFSE 2024 · 1 citation
- type++: Prohibiting Type Confusion with Inline Type InformationNicolas Badoux, Flavio Toffalini, Yuseok Jeon, Mathias PayerNDSS 2025
- Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain AttacksGaoning Pan, Yiming Tao, Qinying Wang, Chunming Wu et al.NDSS 2026
Builds on16
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
Related papers
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
- Don't Waste My Efforts: Pruning Redundant Sanitizer Checks by Developer-Implemented Type ChecksYizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan et al.USENIX Security 2024 · 8 citations
- Rusted Types: Static Detection of Rust Type Confusion BugsZeyang Zhuang, Wei Meng, Michael R. LyuICSE 2026
- TYPEPULSE: Detecting Type Confusion Bugs in Rust ProgramsHung-Mao Chen, Xu He, Shu Wang, Xiaokuan Zhang et al.USENIX Security 2025
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo et al.USENIX Security 2025
