Lune

USENIX Security2026顶会

Wormholes in the File System: Understanding the Misunderstanding of Symlinks

Yongheng Liu, Lei Zhang, Yuhang Zhao, Yuzhou He

出版方
2026年份

摘要

Symlinks, a file system feature supported at the operating system level for more than four decades, are deeply integrated across the software stack, making them an indispensable component of modern computing environments. The symlink mechanism is highly flexible, allowing references to nearly any location in the file system and enabling complex resolution behaviors. However, this flexibility also introduces significant misunderstandings for developers, which has led to widespread misuse and become a primary vector for critical security vulnerabilities in file-handling software, e.g., arbitrary file write and code execution.

In this paper, we present the first systematic study of how symlinks are incorrectly handled and the substantial security risks. Specifically, we study how programming language standard libraries improperly utilize symlink-related system calls, and how such misuse and misunderstanding propagates to downstream applications which results in various inadequate path validations. To further understand whether these inadequate path validations could be exploited in real world, we design and implement five path validation bypass schemes and three arbitrary write methods. Our evaluation across 85 projects uncovered 16 arbitrary file write vulnerabilities, two of which have been assigned high-severity CVEs. We also demonstrate their severe impacts in real-world scenarios and propose multiple mitigation strategies. We have responsibly disclosed these issues to the affected vendors.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper10

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖