CCS2025
Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields
Hao Zhang, Jian Liu, Jie Lu, Shaomin Chen, Tianshuo Han, Bolun Zhang, Xiaorui Gong
Abstract
Linux kernel vulnerabilities represent a critical security threat in modern computing systems, with hundreds of new vulnerabilities discovered annually. Traditional security practices often discard vulnerabilities offering only weak primitives as "unexploitable", creating a significant blind spot in kernel security. This paper presents a novel approach to revive these previously discarded vulnerabilities by exploiting Control Metadata Fields (CMFs) within Linux objects, rather than traditional pointer manipulation. Our CMF-based method overcomes two major limitations of existing approaches: it bypasses modern security measures like pointer authentication code and eliminates the need for precise pointer alignment that weak primitives cannot reliably achieve. Using MetaXploit, our automated analysis tool, we identified 54 exploitable CMFs across Ubuntu and Debian distributions. Empirical testing against 20 real-world vulnerabilities demonstrated successful exploitation in 18 cases, including 12 previously discarded vulnerabilities. These results challenge traditional assumptions about vulnerability exploitability and suggest that many discarded vulnerabilities in the Linux kernel warrant reevaluation.
