Fence2Pwn: KFENCE-Enabled Kernel Exploitation Bypassing Slab Hardening and Memory Tagging
Ernesto Martínez García, Lukas Maar, Martin Unterguggenberger, Stefan Mangard
摘要
While the Linux kernel remains a prime target due to its privileged execution model, exploitation has become substantially more difficult in recent years. Kernel hardening efforts have increasingly focused on the slab allocator, aiming to mitigate entire vulnerability classes (e.g., via memory tagging) or disrupt exploit techniques (e.g., via heap object segregation). However, it remains unclear whether these protections are consistently enforced across all allocation paths. In this paper, we find that one allocation path is excluded from all state-of-the-art slab defenses: the path used for KFENCE allocations. KFENCE is designed as a low-overhead sampling-based memory-safety error detector for production kernels. It is enabled by default and active in billions of systems including on Android, Red Hat Enterprise Linux, and most Linux distributions. We show that it unintentionally enables a new exploit technique, Fence2Pwn. Concretely, Fence2Pwn leverages several KFENCE-specific behaviors. Three are particularly notable: (i) using a timing side channel, we detect when the kernel falls back to KFENCE allocations; (ii) KFENCE allocations are served by KFENCE-managed caches rather than size- and type-segregated slab caches, enabling bypass of heap segregation; and (iii) KFENCE allocations are untagged, enabling bypass of memory tagging. We evaluate Fence2Pwn by profiling our timing side channel, KFENCE's object slot dynamics as well as different environments and noise floors. Finally, we demonstrate that Fence2Pwn exploits this slab-defense gap: Fence2Pwn uses KFENCE to exploit an existing UAF-based memory-reuse vulnerability, which allows it to overlay security-relevant objects of different types and sizes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- DirtyCred: Escalating Privilege in Linux KernelZhenpeng Lin, Yuhang Wu, Xinyu XingCCS 2022 · 被引用 30 次
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber 等USENIX Security 2024 · 被引用 16 次
- RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel ProtectionsKyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing 等CCS 2023 · 被引用 9 次
- DirtyFree: Simplified Data-Oriented Programming in the Linux KernelYoochan Lee, Hyuk Kwon, Thorsten HolzNDSS 2026 · 被引用 1 次
相关 Paper
- Pspray: Timing Side-Channel based Linux Kernel Heap Exploitation TechniqueYoochan Lee, Jinhan Kwak, Junesoo Kang, Yuseok Jeon 等USENIX Security 2023
- When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel LeaksLukas Maar, Lukas Giner, Daniel Gruss, Stefan MangardUSENIX Security 2025
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 被引用 76 次
- SeaK: Rethinking the Design of a Secure Allocator for OS KernelZicheng Wang, Yicheng Guang, Yueqi Chen, Zhenpeng Lin 等USENIX Security 2024 · 被引用 1 次
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee 等S&P 2026
