Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China
Shencha Fan, Jackson Sippe, Sakamoto San, Jade Sheffey, David Fifield, Amir Houmansadr, Elson Wedwards, Eric Wustrow
Abstract
We present textitWallbleed, a buffer over-read vulnerability that existed in the DNS injection subsystem of the Great Firewall of China. Wallbleed caused certain nation-wide censorship middleboxes to reveal up to 125 bytes of their memory when censoring a crafted DNS query. It afforded a rare insight into one of the Great Firewall's well-known network attacks, namely DNS injection, in terms of its internal architecture and the censor's operational behaviors.
To understand the causes and implications of Wallbleed, we conducted longitudinal and Internet-wide measurements for over two years from October 2021. We (1) reverse-engineered the injector's parsing logic, (2) evaluated what information was leaked and how Internet users inside and outside of China were affected, and (3) monitored the censor's patching behaviors over time. We identified possible internal traffic of the censorship system, analyzed its memory management and load-balancing mechanisms, and observed process-level changes in an injector node. We employed a new side channel to distinguish the injector's multiple processes to assist our analysis. Our monitoring revealed that the censor coordinated an incorrect patch for Wallbleed in November 2023 and fully patched it in March 2024.
Wallbleed exemplifies that the harm censorship middleboxes impose on Internet users is even beyond their obvious infringement of freedom of expression. When implemented poorly, it also imposes severe privacy and confidentiality risks to Internet users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman et al.CCS 2025
- Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible FutureHarshini Sri Ramulu, Helen Schmitt, Bogdan Rerich, Rachel Gonzalez Rodriguez et al.CCS 2025
- Exposing and Circumventing SNI-based QUIC Censorship of the Great Firewall of ChinaAli Zohaib, Qiang Zao, Jackson Sippe, Abdulrahman Alaraj et al.USENIX Security 2025
- A Wall Behind A Wall: Emerging Regional Censorship in ChinaMingshi Wu, Ali Zohaib, Zakir Durumeric, Amir Houmansadr et al.S&P 2025
- CircumVolve: Automated Discovery of Censorship Evasion Strategies Using Large Language ModelsAli Zohaib, Jackson Sippe, Jade Sheffey, Mingshi Wu et al.CCS 2026
Related papers
- GFWeb: Measuring the Great Firewall's Web Censorship at ScaleNguyen Phong Hoang, Jakub Dalek, Masashi Crete-Nishihata, Nicolas Christin et al.USENIX Security 2024 · 22 citations
- How Great is the Great Firewall? Measuring China's DNS CensorshipNguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel et al.USENIX Security 2021 · 80 citations
- Technical Analysis of the Geedge Networks Firewall Source Code LeakAnna Ablove, Johnnie Walker, Ben Wolin, Niklas Niere et al.USENIX Security 2026
- Chinese Wall or Swiss Cheese? Keyword filtering in the Great Firewall of ChinaZachary Weinberg, Diogo Barradas, Nicolas ChristinWWW 2021 · 33 citations
- IRBlock: A Large-Scale Measurement Study of the Great Firewall of IranJonas Tai, Karthik Nishanth Sengottuvelavan, Peter Whiting, Nguyen Phong HoangUSENIX Security 2025
