USENIX Security2026Top-tier venue
Melting the Flesh of PHP's Memory Hardening
Yifan Wu, Xiaochuan Yu, Zhiyun Qian
Abstract
Heap allocators are responsible for efficiently allocating or releasing memory on the heap. In addition, they also commonly implement various mitigation measures to defend against heap-based memory corruption. Recently, the PHP project launched a heap hardening initiative aimed at stopping popular heap exploit techniques or restricting the exploit strategy space. In this paper, we conduct the first security study to understand the impact and effectiveness of these new protective measures. We find that while they are effective at stopping current-generation exploits, they fall short against determined attackers who will adapt. Through our analysis, we not only identify the flaw that allows specific mitigations to be bypassed, but also a new suite of novel exploitation strategies that work for the most common vulnerabilities involving out-of-bounds memory write and use-after-free write primitives. Notably, our strategy is generic across the built-in PHP objects and can still work even with a single-byte out-of-bounds memory write primitive. Finally, we evaluate our exploit strategies against five real vulnerabilities in an environment with all evaluated protections enabled. The results show that although the new protection measures can effectively defend against the exploitation of most vulnerabilities, the attack strategies proposed by this work can still make these vulnerabilities exploitable again. The identified flaw has since been patched after our responsible disclosure.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c3eb3d0c-eca1-4578-94f0-caeb2e72b612Builds on9
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
- Gollum: Modular and Greybox Exploit Generation for Heap Overflows in InterpretersSean Heelan, Tom Melham, Daniel KroeningCCS 2019 · 50 citations
- Guarder: A Tunable Secure AllocatorSam Silvestro, Hongyu Liu, Tianyi Liu, Zhiqiang Lin et al.USENIX Security 2018 · 39 citations
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber et al.USENIX Security 2024 · 16 citations
- Top of the Heap: Efficient Memory Error Protection of Safe Heap ObjectsKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.CCS 2024 · 3 citations
Related papers
- HeapHopper: Bringing Bounded Model Checking to Heap Implementation SecurityMoritz Eckert, Antonio Bianchi, Ruoyu Wang, Yan Shoshitaishvili et al.USENIX Security 2018 · 62 citations
- Automatic Heap Layout Manipulation for ExploitationSean Heelan, Tom Melham, Daniel KroeningUSENIX Security 2018 · 62 citations
- Automatic Techniques to Systematically Discover New Heap Exploitation PrimitivesInsu Yun, Dhaval Kapil, Taesoo KimUSENIX Security 2020
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee et al.S&P 2026
- CAMP: Compiler and Allocator-based Heap Memory ProtectionZhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni et al.USENIX Security 2024 · 14 citations
