SCAVY: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation
Erin Avllazagaj, Yonghwi Kwon, Tudor Dumitras
摘要
Kernel privilege-escalation exploits typically leverage memory-corruption vulnerabilities to overwrite particular memory locations. These memory corruption targets play a critical role in the exploits, as they determine which privileged resources (e.g. files, memory, and operations) the adversary may access and what privileges (e.g. read, write, and unrestricted) they may gain. While prior research has made important advances in discovering vulnerabilities, and in automating their exploitation, it relies on the few memory corruption targets that have been discovered manually so far. We propose SCAVY, a framework that automatically discovers memory corruption targets for privilege escalation in the Linux kernel. The key insight behind SCAVY is to extend the search beyond the kernel data structures that include function pointers, or pointers to such structures, and that were studied in prior work while accounting for approximately one tenth of the kernel structures. Additionally, the search is bug-type agnostic, as it considers any memory corruption capability. To this end, we develop novel and scalable techniques that combine fuzzing and differential analysis to automatically explore and detect privilege escalation by comparing the accessibility of resources between executions with and without corruption. This allows SCAVY to determine that corrupting a certain field puts the system in an exploitable state, independently of the vulnerability exploited. SCAVY found 955 PoC, from which we identify 17 fields belonging to 12 structures -when corrupted they have shown to reach a privilege escalation state. We further develop 6 exploits for 5 vulnerabilities. Our findings show that memory corruption targets can change the security implications of vulnerabilities, urging researchers to proactively discover memory corruption targets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 被引用 1 次
- Optimizing Input Minimization in Kernel FuzzingHui Guo, Hao Sun, Shan Huang, Ting Su 等USENIX ATC 2025 · 被引用 1 次
- Discovering, characterizing and exploiting controllable-copy objects for kernel data-only attacks with CopyKatJakob Koschel, Andrea Mambretti, Alessandro Sorniotti, Pietro Moretto 等USENIX Security 2026
- System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the SystemJennifer Miller, Manas Ghandat, Kyle Zeng, Hongkai Chen 等USENIX Security 2025
- Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain AttacksGaoning Pan, Yiming Tao, Qinying Wang, Chunming Wu 等NDSS 2026
它引用的顶会 Paper15
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 被引用 174 次
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 被引用 139 次
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing 等USENIX Security 2018 · 被引用 124 次
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 被引用 76 次
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 被引用 75 次
相关 Paper
- BridgeRouter: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux KernelDongchen Xie, Dongnan He, Wei You, Jianjun Huang 等S&P 2025
- KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write VulnerabilitiesWeiteng Chen, Xiaochen Zou, Guoren Li, Zhiyun QianUSENIX Security 2020
- SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept ExploitsWei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang 等CCS 2017 · 被引用 148 次
- K-Miner: Uncovering Memory Corruption in LinuxDavid Gens, Simon Schmitt, Lucas Davi, Ahmad-Reza SadeghiNDSS 2018 · 被引用 58 次
- AlphaEXP: An Expert System for Identifying Security-Sensitive Kernel ObjectsRuipeng Wang, Kaixiang Chen, Chao Zhang, Zulie Pan 等USENIX Security 2023
