Check It Again: Detecting Lacking-Recheck Bugs in OS Kernels
Wenwen Wang, Kangjie Lu, Pen-Chung Yew
摘要
Operating system kernels carry a large number of security checks to validate security-sensitive variables and operations. For example, a security check should be embedded in a code to ensure that a user-supplied pointer does not point to the kernel space. Using security-checked variables is typically safe. However, in reality, security-checked variables are often subject to modification after the check. If a recheck is lacking after a modification, security issues may arise, e.g., adversaries can control the checked variable to launch critical attacks such as out-of-bound memory access or privilege escalation. We call such cases lacking-recheck (LRC) bugs, a subclass of TOCTTOU bugs, which have not been explored yet. In this paper, we present the first in-depth study of LRC bugs and develop LRSan, a static analysis system that systematically detects LRC bugs in OS kernels. Using an inter-procedural analysis and multiple new techniques, LRSan first automatically identifies security checks, critical variables, and uses of the checked variables, and then reasons about whether a modification is present after a security check. A case in which a modification is present but a recheck is lacking is an LRC bug. We apply LRSan to the latest Linux kernel and evaluate the effectiveness of LRSan. LRSan reports thousands of potential LRC cases, and we have confirmed 19 new LRC bugs. We also discuss patching strategies of LRC bugs based on our study and bug-fixing experience.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper28
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
- NtFuzz: Enabling Type-Aware Kernel Fuzzing on Windows with Static Binary AnalysisJaeseung Choi, Kangsu Kim, Daejin Lee, Sang Kil ChaS&P 2021 · 被引用 61 次
- SHARD: Fine-Grained Kernel Specialization with Context-Aware HardeningMuhammad Abubakar, Adil Ahmad, Pedro Fonseca, Dongyan XuUSENIX Security 2021 · 被引用 47 次
- Finding Bugs Using Your Own Code: Detecting Functionally-similar yet Inconsistent CodeMansour Ahmadi, Reza Mirzazade Farkhani, Ryan Williams, Long LuUSENIX Security 2021 · 被引用 41 次
它引用的顶会 Paper12
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 被引用 326 次
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
相关 Paper
- Static Detection of TOCTOU Bugs Caused by Kernel RacesGui-Dong Han, Jia-Ju Bai, Qiu-Ji Chen, Jiqiang LuUSENIX Security 2026
- CPscan: Detecting Bugs Caused by Code Pruning in IoT KernelsLirong Fu, Shouling Ji, Kangjie Lu, Peiyu Liu 等CCS 2021 · 被引用 7 次
- DR. CHECKER: A Soundy Analysis for Linux Kernel DriversAravind Machiry, Chad Spensky, Jake Corina, Nick Stephens 等USENIX Security 2017 · 被引用 126 次
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- Detecting Kernel Refcount Bugs with Two-Dimensional Consistency CheckingXin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu 等USENIX Security 2021 · 被引用 26 次
