EntryBleed: A Universal KASLR Bypass against KPTI on Linux

EntryBleed: A Universal KASLR Bypass against KPTI on Linux
复制标题

DOI:
10.1145/3623652.3623669
复制
发表时间:
2023-10
期刊:
Proceedings of the 12th International Workshop on Hardware and Architectural Support for Security and Privacy
影响因子:
--
通讯作者:
William Liu;Joseph Ravichandran;Mengjia Yan
William Liu;Joseph Ravichandran;Mengjia Yan
中科院分区:
其他
文献类型:
--
作者:
William Liu;Joseph Ravichandran;Mengjia Yan

文献摘要

相似文献

多年来,攻击者通过开发依赖于内核代码和数据段的已知位置的漏洞来危害系统。KASLR(内核地址空间布局随机化)是现代操作系统中的一个关键缓解措施,它通过内核映像基址的运行时随机化来阻止这些攻击。KPTI(内核页表隔离)是另一种防御机制,最初是为了在用户代码执行期间通过取消映射内核地址来防御2018年Meltdown攻击。这种安全机制使得攻击者更难通过微架构侧通道泄漏内核地址映射。然而,为了用户到内核上下文的转换,一些用于系统调用和中断处理的页面被免除了隔离。我们将EntryBleed漏洞(CVE-2022-4543)作为针对KASLR保护机制的通用旁路,通过微架构侧通道和英特尔CPU上KPTI缓解中的设计缺陷的组合。我们证明了我们发现的错误可以在物理主机和硬件加速虚拟机环境中的现代英特尔CPU上在一秒钟内准确地对内核地址空间进行去随机化。然后,我们提供了一个根本原因分析,以定位在物理和虚拟化环境中启用EntryBleed的核心微架构行为。此外,我们提出了一个高性能的缓解密切基于预先存在的KASLR硬化机制。如果不打补丁,攻击者将能够轻松绕过KASLR,大大降低了开发漏洞的障碍,并增加了对Linux操作系统的严重威胁的风险。
For years, attackers have compromised systems by developing exploits that rely on known locations of kernel code and data segments. KASLR (Kernel Address Space Layout Randomization) is a key mitigation in modern operating systems which hampers these attacks through runtime randomization of the kernel image base address. KPTI (Kernel Page Table Isolation) is another defense mechanism, originally introduced to defend against the 2018 Meltdown attack by unmapping kernel addresses during user code execution. This security mechanism makes it harder for attackers to leak kernel address mappings through micro-architectural side channels. However, a few pages for system call and interrupt handling were exempted from isolation for the sake of user to kernel context transitions. We present the EntryBleed vulnerability (CVE-2022-4543) as a universal bypass against the KASLR protection mechanism through a combination of micro-architectural side channels and design flaws in the KPTI mitigation on Intel CPUs. We demonstrate that the bug we identified can accurately de-randomize the kernel address space within a second on modern Intel CPUs in both physical host and hardware-accelerated virtual machine environments. We then provide a root cause analysis to locate the core micro-architectural behaviors that enable EntryBleed, both on physical and under virtualized environments. Furthermore, we propose a performant mitigation based closely upon a pre-existing KASLR hardening mechanism. If left unpatched, attackers will be able to easily bypass KASLR, greatly lowering the barrier for exploit development and increasing the risk of serious threats against the Linux operating system.