HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit Techniques
Yoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee, Thorsten Holz
摘要
As kernel mitigations that reduce exploit success rates continue to be deployed, exploitation techniques have become increasingly sophisticated to maintain high reliability under such constrained environments. These techniques, however, fundamentally rely on precise knowledge of the locations of kernel heap objects-information that is not available to unprivileged users and forces attackers to depend on coarse and speculative inferences about allocator behavior. As a result, existing exploit techniques inevitably exhibit structural failure cases when vulnerable or target objects occupy unexpected intra-page positions. To address this limitation, we present Heap localization, the first primitive that enables objectlevel heap layout inference in the Linux kernel. Heap LOCALIZATION recovers the precise intra-page offset of kernel heap objects by exploiting deterministic VIPT L1 cache behavior, enabling deterministic object placement without requiring memory disclosure. By providing exact object-location information, Heap Localization eliminates layout-induced failure cases and transforms several previously probabilistic heap exploitation techniques into deterministic ones. Our evaluation demonstrates that Heap Localization consistently localizes and reliably positions objects, achieving average success rates of 99.3 % in the idle state and 95.7 % under heavy load. We further demonstrate its practicality by applying Heap Localization to real-world kernel vulnerabilities, where it significantly increases exploit reliability.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit ReliabilityKyle Zeng, Yueqi Chen, Haehyun Cho, Xinyu Xing 等USENIX Security 2022
- SeaK: Rethinking the Design of a Secure Allocator for OS KernelZicheng Wang, Yicheng Guang, Yueqi Chen, Zhenpeng Lin 等USENIX Security 2024 · 被引用 1 次
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 被引用 76 次
- When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel LeaksLukas Maar, Lukas Giner, Daniel Gruss, Stefan MangardUSENIX Security 2025
- BridgeRouter: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux KernelDongchen Xie, Dongnan He, Wei You, Jianjun Huang 等S&P 2025
