arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.37608cs.CR

SLUB 的丰收季:从 io_uring 漏洞到基于 sheaf 的新型利用技术

Harvest Season for SLUB: From io_uring vulnerability to Novel Sheaf-Based Exploitation Techniques

Hao-Yu Yang, Yu-Ting Lin

AI总结:

本研究分析 Linux 6.18 中 io_uring 与 SLUB 的 sheaf/barn 机制,发现两个新漏洞并构建权限提升链,提出三种基于 sheaf 的新型利用技术,揭示其作为新攻击面的潜力。

AI中文摘要:

Linux 内核为提高 I/O 性能和更高效的内存管理而引入的新机制,在提升性能的同时也开辟了新的攻击面。本研究将其中两个机制放在一起考察:io_uring 子系统以及 Linux 6.18 中添加到 SLUB 分配器中的 sheaf/barn 缓存机制。本研究中提出了 io_uring 中两个此前未知的漏洞,并将其中一个在加固内核配置下发展成完整的本地权限提升链。构建该利用链揭示了 sheaf/barn 机制改变了诸如跨缓存攻击等既有利用技术背后的长期假设,且其设计也削弱了现有 SLUB 空闲链表保护。这两项观察均被分析并转化为可用的原语。基于此分析,提出了三种新颖的基于 sheaf 的利用技术。其中,一种 RCU-sheaf 跨缓存技术消除了跨缓存移动对象时对 buddy 系统的传统依赖,从而在缓存池之间的对象迁移上提供了更灵活、更可靠的控制。综合这些结果,将 sheaf/barn 层刻画为 Linux 内核利用中一个新颖且很大程度上未被探索的攻击面。

英文摘要:

The Linux kernel's push for higher I/O performance and more efficient memory management has introduced new mechanisms that, while improving performance, also open new attack surfaces. This research examines two of them together: the io_uring subsystem and the sheaf/barn caching mechanism added to the SLUB allocator in Linux 6.18. In this research, two previously unknown vulnerabilities in io_uring are presented, and one is developed into a complete local privilege escalation chain under a hardened kernel configuration. Building this chain revealed that the sheaf/barn mechanism changes long-standing assumptions behind established exploitation techniques such as cross-cache attack, and that its design also weakens existing SLUB freelist protections. Both observations are analyzed and turned into working primitives. Building on this analysis, three novel sheaf-based exploitation techniques are proposed. Among them, an RCU-sheaf cross-cache technique removes the traditional dependence on the buddy system for moving objects across caches, giving more flexible and reliable control over object migration between cache pools. Together, these results characterize the sheaf/barn layer as a new and largely unexplored attack surface in Linux kernel exploitation.

↑