SafeFetch: Practical Double-Fetch Protection with Kernel-Fetch Caching
Victor Duta, Mitchel Aloserij, Cristiano Giuffrida
摘要
Double-fetch bugs (or vulnerabilities) stem from in-kernel system call execution fetching the same user data twice without proper data (re)sanitization, enabling TOCT-TOU attacks and posing a major threat to operating systems security. Existing double-fetch protection systems rely on the MMU to trap on writes to syscall-accessed user pages and provide the kernel with a consistent snapshot of user memory. While this strategy can hinder attacks, it also introduces nontrivial runtime performance overhead due to the cost of trapping/remapping and the coarse (page-granular) write interposition mechanism. In this paper, we propose SafeFetch, a practical solution to protect the kernel from double-fetch bugs. The key intuition is that most system calls fetch small amounts of user data (if at all), hence caching this data in the kernel can be done at a small performance cost. To this end, SafeFetch creates per-syscall caches to persist fetched user data and replay them when they are fetched again within the same syscall. This strategy neutralizes all double-fetch bugs, while eliminating trapping/remapping overheads and relying on efficient byte-granular interposition. Our Linux prototype evaluation shows SafeFetch can provide comprehensive protection with low performance overheads (e.g., 4.4% geomean on LMBench), significantly outperforming state-of-the-art solutions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel IsolationYingjie Cao, Xiaogang Zhu, Dean Sullivan, Haowei Yang 等NDSS 2026 · 被引用 1 次
- Dynamic Detection of Vulnerable DMA Race ConditionsBrian Johannesmeyer, Raphael Isemann, Cristiano Giuffrida, Herbert BosCCS 2025
- Static Detection of TOCTOU Bugs Caused by Kernel RacesGui-Dong Han, Jia-Ju Bai, Qiu-Ji Chen, Jiqiang LuUSENIX Security 2026
它引用的顶会 Paper7
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- How Double-Fetch Situations turn into Double-Fetch Vulnerabilities: A Study of Double Fetches in the Linux KernelPengfei Wang, Jens Krinke, Kai Lu, Gen Li 等USENIX Security 2017 · 被引用 66 次
- Midas: Systematic Kernel TOCTTOU ProtectionAtri Bhattacharyya, Uros Tesic, Mathias PayerUSENIX Security 2022
- SecureCells: A Secure Compartmentalized ArchitectureAtri Bhattacharyya, Florian Hofhammer, Yuanlong Li, Siddharth Gupta 等S&P 2023
- Silent Bugs Matter: A Study of Compiler-Introduced Security BugsJianhao Xu, Kangjie Lu, Zhengjie Du, Zhu Ding 等USENIX Security 2023
相关 Paper
- WarpAttack: Bypassing CFI through Compiler-Introduced Double-FetchesJianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao 等S&P 2023
- Check It Again: Detecting Lacking-Recheck Bugs in OS KernelsWenwen Wang, Kangjie Lu, Pen-Chung YewCCS 2018 · 被引用 49 次
- Don't shoot down TLB shootdowns!Nadav Amit, Amy Tai, Michael WeiEuroSys 2020 · 被引用 32 次
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang 等USENIX Security 2021 · 被引用 53 次
- Using Trātṛ to tame Adversarial SynchronizationYuvraj Patel, Chenhao Ye, Akshat Sinha, Abigail Matthews 等USENIX Security 2022
