WarpAttack: Bypassing CFI through Compiler-Introduced Double-Fetches
Jianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao, Mathias Payer
Abstract
Code-reuse attacks are dangerous threats that attracted the attention of the security community for years. These attacks aim at corrupting important control-flow transfers for taking control of a process without injecting code. Nowadays, the combinations of multiple mitigations (e.g., ASLR, DEP, and CFI) drastically reduced this attack surface, making running code-reuse exploits more challenging.Unfortunately, security mitigations are combined with compiler optimizations, that do not distinguish between security-related and application code. Blindly deploying code optimizations over code-reuse mitigations may undermine their security guarantees. For instance, compilers may introduce double-fetch vulnerabilities that lead to concurrency issues such as Time-Of-Check to Time-Of-Use (TOCTTOU) attacks.In this work, we propose a new attack vector, called WarpAttack, that exploits compiler-introduced double-fetch optimizations to mount TOCTTOU attacks and bypass code-reuse mitigations. We study the mechanism underlying this attack and present a practical proof-of-concept exploit against the last version of Firefox. Additionally, we propose a lightweight analysis to locate vulnerable double-fetch code (with 3% false positives) and conduct research over six popular applications, five operating systems, and four architectures (32 and 64 bits) to study the diffusion of this threat. Moreover, we study the implication of our attack against six CFI implementations. Finally, we investigate possible research lines for addressing this threat and propose practical solutions to be deployed in existing projects.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- On Bridging the Gap between Control Flow Integrity and Attestation SchemesMahmoud Ammar, Ahmed Abdelraoof, Silviu VlasceanuUSENIX Security 2024 · 9 citations
- Cryptographically Enforced Memory SafetyMartin Unterguggenberger, David Schrammel, Lukas Lamster, Pascal Nasahl et al.CCS 2023 · 6 citations
- SafeFetch: Practical Double-Fetch Protection with Kernel-Fetch CachingVictor Duta, Mitchel Aloserij, Cristiano GiuffridaUSENIX Security 2024 · 2 citations
- IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel IsolationYingjie Cao, Xiaogang Zhu, Dean Sullivan, Haowei Yang et al.NDSS 2026 · 1 citation
- Manipulative Interference AttacksSamuel Mergendahl, Stephen Fickas, Boyana Norris, Richard SkowyraCCS 2024 · 1 citation
Builds on15
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
Related papers
- Not so fast: understanding and mitigating negative impacts of compiler optimizations on code reuse gadget setsMichael D. Brown, Matthew Pruett, Robert Bigelow, Girish Mururu et al.OOPSLA 2021 · 11 citations
- Cross-Language AttacksSamuel Mergendahl, Nathan Burow, Hamed OkhraviNDSS 2022
- Methodologies for Quantifying (Re-)randomization Security and Timing under JIT-ROPSalman Ahmed, Ya Xiao, Kevin Z. Snow, Gang Tan et al.CCS 2020 · 21 citations
- Return to the Zombie Gadgets: Undermining Destructive Code Reads via Code Inference AttacksKevin Z. Snow, Roman Rogowski, Jan Werner, Hyungjoon Koo et al.S&P 2016 · 54 citations
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 8 citations
