From Release to Rebirth: Exploiting Thanos Objects in Linux Kernel

From Release to Rebirth: Exploiting Thanos Objects in Linux Kernel
复制标题

从发布到重生:在 Linux 内核中利用 Thanos 对象

DOI:
10.1109/tifs.2022.3226906
复制
发表时间:
2023
影响因子:
6.8
通讯作者:
Wang Baosheng
Wang Baosheng
中科院分区:
计算机科学1区
文献类型:
--
作者:
Liu Danjun;Wang Pengfei;Zhou Xu;Xie Wei;Zhang Gen;Luo Zhenhao;Yue Tai;Wang Baosheng

文献摘要

参考文献

相似文献

漏洞修复是耗时的,因此,并不是所有发现的漏洞都可以及时修复。实际上,开发人员根据可利用性优先修复漏洞。大量的漏洞被延迟修补,甚至被忽略,因为它们被认为是“不可利用的”或由于难以利用弱原语而被低估。然而,漏洞可能已经在野外。在本文中,利用弱原语,传统的方法无法利用,我们提出了一种通用的开发策略,可以将弱利用原语到强利用原语。基于内核中名为Thanos对象的特殊对象,我们的方法可以利用没有函数指针解引用的UAF漏洞和具有有限写入长度和值的OOB写入漏洞。该方法克服了传统的漏洞利用策略严重依赖漏洞自身能力的不足。为了方便使用Thanos对象,我们设计了一个名为TAODE的工具来自动从内核中搜索符合条件的Thanos对象。然后,通过约束的复杂性来评估所识别的Thanos对象的可用性。最后,它将漏洞与合格的Thanos对象配对。我们已经用真实世界的内核评估了我们的方法。TAODE成功地从Linux中识别出了许多Thanos对象。使用已识别的Thanos对象,我们用20个现实世界的漏洞证明了我们方法的可行性,其中大多数传统技术未能利用。通过实验,我们发现,除了利用弱原语,我们的方法有时可以绕过内核SMAP机制(CVE-2016-10150,CVE-2016-0728),更好地利用泄漏的堆指针地址(CVE-2022-25636),甚至理论上可以破解某些漏洞补丁(例如,双自由)。
Vulnerability fixing is time-consuming, hence, not all of the discovered vulnerabilities can be fixed timely. In reality, developers prioritize vulnerability fixing based on exploitability. Large numbers of vulnerabilities are delayed to patch or even ignored as they are regarded as “unexploitable” or underestimated owing to the difficulty in exploiting the weak primitives. However, exploits may have been in the wild. In this paper, to exploit the weak primitives that traditional approaches fail to exploit, we propose a versatile exploitation strategy that can transform weak exploit primitives into strong exploit primitives. Based on a special object in the kernel named Thanos object, our approach can exploit a UAF vulnerability that does not have function pointer dereference and an OOB write vulnerability that has limited write length and value. Our approach overcomes the shortage that traditional exploitation strategies heavily rely on the capability of the vulnerability. To facilitate using Thanos objects, we devise a tool named TAODE to automatically search for eligible Thanos objects from the kernel. Then, it evaluates the usability of the identified Thanos objects by the complexity of the constraints. Finally, it pairs vulnerabilities with eligible Thanos objects. We have evaluated our approach with real-world kernels. TAODE successfully identified numerous Thanos objects from Linux. Using the identified Thanos objects, we proved the feasibility of our approach with 20 real-world vulnerabilities, most of which traditional techniques failed to exploit. Through the experiments, we find that in addition to exploiting weak primitives, our approach can sometimes bypass the kernel SMAP mechanism (CVE-2016-10150, CVE-2016-0728), better utilize the leaked heap pointer address (CVE-2022-25636), and even theoretically break certain vulnerability patches (e.g., double-free).
DOI: --
发表时间: 2022
期刊: --
影响因子: --
作者:
Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
通讯作者: Kyle Zeng;Yueqi Chen;Haehyun Cho;Xinyu Xing;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
DOI: --
发表时间: 2010-10
期刊: --
影响因子: --
作者:
Информатика
通讯作者: Информатика
DOI: --
发表时间: 2021-11
期刊: ArXiv
影响因子: --
作者:
Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian
通讯作者: Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian
DOI: --
发表时间: 2018
期刊: --
影响因子: --
作者:
Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou
通讯作者: Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou
DOI: --
发表时间: 2020
期刊: --
影响因子: --
作者:
Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
通讯作者: Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn