Wormholes in the File System: Understanding the Misunderstanding of Symlinks
Yongheng Liu, Lei Zhang, Yuhang Zhao, Yuzhou He
摘要
Symlinks, a file system feature supported at the operating system level for more than four decades, are deeply integrated across the software stack, making them an indispensable component of modern computing environments. The symlink mechanism is highly flexible, allowing references to nearly any location in the file system and enabling complex resolution behaviors. However, this flexibility also introduces significant misunderstandings for developers, which has led to widespread misuse and become a primary vector for critical security vulnerabilities in file-handling software, e.g., arbitrary file write and code execution.
In this paper, we present the first systematic study of how symlinks are incorrectly handled and the substantial security risks. Specifically, we study how programming language standard libraries improperly utilize symlink-related system calls, and how such misuse and misunderstanding propagates to downstream applications which results in various inadequate path validations. To further understand whether these inadequate path validations could be exploited in real world, we design and implement five path validation bypass schemes and three arbitrary write methods. Our evaluation across 85 projects uncovered 16 arbitrary file write vulnerabilities, two of which have been assigned high-severity CVEs. We also demonstrate their severe impacts in real-world scenarios and propose multiple mitigation strategies. We have responsibly disclosed these issues to the affected vendors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes 等NDSS 2018 · 被引用 86 次
- Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationZhi Li, Weijie Liu, XiaoFeng Wang, Bin Yuan 等CCS 2023 · 被引用 6 次
- On the Abuse and Detection of Polyglot FilesLuke Koch, Sean Oesch, Amir Sadovnik, Brian Weber 等WWW 2025
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
相关 Paper
- Pig in a Poke: Automatically Detecting and Exploiting Link Following Vulnerabilities in Windows File OperationsBocheng Xiang, Yuan Zhang, Fengyu Liu, Hao Huang 等USENIX Security 2025
- Windows plays Jenga: Uncovering Design Weaknesses in Windows File System SecurityDong-uk Kim, JunYoung Park, Sanghak Oh, Hyoungshick Kim 等CCS 2025
- File Hijacking Vulnerability: The Elephant in the RoomChendong Yu, Yang Xiao, Jie Lu, Yuekang Li 等NDSS 2024
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu 等NDSS 2026 · 被引用 3 次
- Bilingual Problems: Studying the Security Risks Incurred by Native Extensions in Scripting LanguagesCristian-Alexandru Staicu, Sazzadur Rahaman, Ágnes Kiss, Michael BackesUSENIX Security 2023
