From Release to Rebirth: Exploiting Thanos Objects in Linux Kernel
From Release to Rebirth: Exploiting Thanos Objects in Linux Kernel
复制标题
从发布到重生:在 Linux 内核中利用 Thanos 对象
DOI:
10.1109/tifs.2022.3226906
复制
发表时间:
2023
影响因子:
6.8
通讯作者:
Wang Baosheng
中科院分区:
文献类型:
--
作者:
Liu Danjun;Wang Pengfei;Zhou Xu;Xie Wei;Zhang Gen;Luo Zhenhao;Yue Tai;Wang Baosheng
Vulnerability fixing is time-consuming, hence, not all of the discovered vulnerabilities can be fixed timely. In reality, developers prioritize vulnerability fixing based on exploitability. Large numbers of vulnerabilities are delayed to patch or even ignored as they are regarded as “unexploitable” or underestimated owing to the difficulty in exploiting the weak primitives. However, exploits may have been in the wild. In this paper, to exploit the weak primitives that traditional approaches fail to exploit, we propose a versatile exploitation strategy that can transform weak exploit primitives into strong exploit primitives. Based on a special object in the kernel named Thanos object, our approach can exploit a UAF vulnerability that does not have function pointer dereference and an OOB write vulnerability that has limited write length and value. Our approach overcomes the shortage that traditional exploitation strategies heavily rely on the capability of the vulnerability. To facilitate using Thanos objects, we devise a tool named TAODE to automatically search for eligible Thanos objects from the kernel. Then, it evaluates the usability of the identified Thanos objects by the complexity of the constraints. Finally, it pairs vulnerabilities with eligible Thanos objects. We have evaluated our approach with real-world kernels. TAODE successfully identified numerous Thanos objects from Linux. Using the identified Thanos objects, we proved the feasibility of our approach with 20 real-world vulnerabilities, most of which traditional techniques failed to exploit. Through the experiments, we find that in addition to exploiting weak primitives, our approach can sometimes bypass the kernel SMAP mechanism (CVE-2016-10150, CVE-2016-0728), better utilize the leaked heap pointer address (CVE-2022-25636), and even theoretically break certain vulnerability patches (e.g., double-free).
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
--
影响因子:
--
作者:
Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
通讯作者:
Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
DOI:
--
发表时间:
2010-10
期刊:
--
影响因子:
--
作者:
Информатика
通讯作者:
Информатика
DOI:
--
发表时间:
2021-11
期刊:
ArXiv
影响因子:
--
作者:
Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian
通讯作者:
Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian
DOI:
--
发表时间:
2018
期刊:
--
影响因子:
--
作者:
Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou
通讯作者:
Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou
DOI:
--
发表时间:
2020
期刊:
--
影响因子:
--
作者:
Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
通讯作者:
Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn