Luci: Loader-based Dynamic Software Updates for Off-the-shelf Shared Objects
Bernhard Heinloth, Peter Wägemann, Wolfgang Schröder-Preikschat
Abstract
Shared libraries indisputably facilitate software development but also significantly increase the attack surface, and when using multiple libraries, frequent patches for vulnerabilities are to be expected. However, such a bugfix commonly requires restarting all services depending on the compromised library, which causes downtimes and unavailability of services. This can be prevented by dynamic software updating, but existing approaches are often costly and incur additional maintenance due to necessary source or infrastructure modifications.
With LUCI, we present a lightweight linker/loader technique to unobtrusively and automatically update shared libraries during runtime by exploiting the indirection mechanisms of position-independent code, hence avoiding severe runtime overhead. LUCI further adds no additional requirements, such as adjusting the source or interfering with the build chain, as it fully adapts to today's build and packageupdate mechanisms of common Linux distributions. We demonstrate our approach on popular libraries (like Expat and libxcrypt) using off-the-shelf (i.e., unmodified) binaries from Debian and Ubuntu packages, being able to update the majority of releases without the necessity of a process restart.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on1
Related papers
- From Global to Local Quiescence: Wait-Free Code Patching of Multi-Threaded ProcessesFlorian Rommel, Christian Dietrich, Birte Friesel, Marcel Köppen et al.OSDI 2020
- RTrace: Towards Better Visibility of Shared Library ExecutionHuaifeng Zhang, Ahmed Ali-EldinNDSS 2026
- One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared librariesHaotian Zhang, Mengfei Ren, Yu Lei, Jiang MingASPLOS 2022 · 18 citations
- An Evil Copy: How the Loader Betrays YouXinyang Ge, Mathias Payer, Trent JaegerNDSS 2017 · 20 citations
- Live Patching for Distributed In-Memory Key-Value StoresMichael Fruth, Stefanie ScherzingerSIGMOD 2025 · 5 citations
