Statically Discover Cross-Entry Use-After-Free Vulnerabilities in the Linux Kernel

Hang Zhang

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · System-Level Security

Overview

Use-After-Free (UAF) vulnerabilities remain one of the most dangerous and prevalent classes of software security issues, despite extensive research and development in automated detection tools. This talk, presented by Hang Zhang at the NDSS Symposium, delves into the persistent challenge of discovering modern UAFs, particularly in large, complex codebases like the Linux kernel. The core problem addressed is the difficulty static analyzers face when the memory allocation, freeing, and subsequent erroneous use occur across different, independent entry functions – a scenario dubbed "cross-entry UAF." Existing tools often struggle with the intricate alias relationships and the nuanced interplay of various code semantics (like locks, conditions, and pointer notifications) that dictate whether a UAF is truly exploitable.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to UAF and its persistent challenge
  2. 0:53 Challenge 1: Cross-entry Use-After-Free vulnerabilities
  3. 2:01 Challenge 2: Reasoning about multiple code aspects
  4. 3:09 UFX: Static analyzer for complex cross-entry UAF
  5. 4:23 UFX: Per-entry analysis and summarization
  6. 5:40 UFX: On-demand query for cross-entry alias pairs
  7. 6:20 UFX: Validating UAF by matching relevant statements
  8. 8:00 UFX: Encoding code semantics for UAF validation

Statically Discover Cross-Entry Use-After-Free Vulnerabilities in the Linux Kernel

Speakers: Hang Zhang

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=vO9SCFS7Z2w

Overview

Use-After-Free (UAF) vulnerabilities remain one of the most dangerous and prevalent classes of software security issues, despite extensive research and development in automated detection tools. This talk, presented by Hang Zhang at the NDSS Symposium, delves into the persistent challenge of discovering modern UAFs, particularly in large, complex codebases like the Linux kernel. The core problem addressed is the difficulty static analyzers face when the memory allocation, freeing, and subsequent erroneous use occur across different, independent entry functions – a scenario dubbed "cross-entry UAF." Existing tools often struggle with the intricate alias relationships and the nuanced interplay of various code semantics (like locks, conditions, and pointer notifications) that dictate whether a UAF is truly exploitable.

The speaker introduces UFX, a novel static analyzer specifically designed to overcome these limitations. UFX aims to systematically identify and validate complex cross-entry UAFs by precisely tracking pointer flows across multiple entry points and encoding diverse code semantics into a unified partial order system for feasibility checking. The significance of this work lies in its ability to uncover a class of UAFs that have historically evaded detection by conventional static analysis, offering a more systematic alternative to dynamic fuzzing for such deeply embedded bugs.

The research highlights that the subtlety of modern UAFs often stems from their distributed nature across multiple execution paths and the complex conditions required for their manifestation. By tackling the challenges of cross-entry alias analysis and comprehensive semantic reasoning, UFX provides a valuable tool for developers and security practitioners. Its findings, including the discovery of zero-day vulnerabilities in critical Linux kernel components, underscore the continued need for sophisticated static analysis techniques to bolster kernel security.

Background

▶ Watch: Introduction to UAF and its persistent challenge (0:00)

The classic Use-After-Free (UAF) vulnerability occurs when a program attempts to access memory that has already been freed. This can lead to various security implications, including data corruption, denial-of-service, or even arbitrary code execution if an attacker can control the re-allocated memory. While the concept is simple, detecting UAFs in real-world, large-scale software systems like the Linux kernel is far from trivial. Many existing static analyzers excel at identifying UAFs within a single function or a straightforward call chain, where the allocation, free, and use patterns are relatively clear and confined.

However, modern UAFs often exhibit a significantly more complex structure, posing two major technical challenges for static analysis:

  1. Cross-Entry Alias Relationships: A significant portion of UAFs in complex codebases like the Linux kernel involves the use and free operations happening in entirely different entry functions. The speaker illustrates this with an example: an object is allocated in entry_function_0, freed, but its dangling pointer is escaped to a global pointer GP. A subsequent call to entry_function_1 might fetch this object via GP and escape it further to GQ. Finally, entry_function_2 accesses the object via GQ, leading to a UAF. Existing static analyzers typically analyze functions in isolation or with limited inter-procedural context, making them "unaware of such cross-entry alias relationship." This prevents them from linking the free event in one entry function to a subsequent use in another.
  1. Comprehensive Semantic Reasoning for Validation: Even if a potential UAF pair (free and use) is identified, validating its feasibility requires reasoning about multiple, interacting code aspects. The speaker provides an example where mechanisms like lock/unlock operations, pointer notifications, and condition rechecks are in place, seemingly designed to prevent UAFs. Yet, a specific interleaving of entry function calls can still trigger the bug. For instance, entry_function_0 might execute a critical section and free an object before notifying a global pointer GP. If entry_function_1 is then invoked, it might pass a condition check (e.g., GP is not null) because the notification hasn't occurred, leading to the UAF. Discerning these subtle timing and state dependencies, especially when they span across different entry functions and involve multiple global variables, is exceedingly difficult for traditional static analysis tools. They struggle to accurately model the precise execution order and the effects of these various synchronization and state-management mechanisms.

These challenges highlight a critical gap in current UAF detection capabilities, particularly for highly concurrent and multi-entry point systems like operating system kernels. The goal of UFX is to bridge this gap by developing a systematic static method that can precisely identify cross-entry alias relationships and comprehensively validate UAF feasibility by considering all relevant code semantics.

Key Findings

▶ Watch: Challenge 2: Reasoning about multiple code aspects (2:01)

UFX demonstrates significant advancements in detecting complex cross-entry Use-After-Free vulnerabilities, particularly within the Linux kernel. The evaluation results showcase its effectiveness and practical value:

  • Superior Bug Finding Capability: On a benchmark dataset of known UAFs collected from the SIS board dashboard, UFX significantly outperformed competitor tools in identifying real-world cross-entry UAFs. This indicates its ability to uncover a class of vulnerabilities that traditional static analyzers often miss due to their limitations in handling multi-entry scenarios.
  • Discovery of Zero-Day Vulnerabilities: UFX was run against 34 Linux kernel device drivers and successfully identified 10 independent cross-entry UAF issues. These were previously unknown, or "zero-day," vulnerabilities, demonstrating UFX's capability to find critical bugs in widely deployed and security-sensitive software components.
  • Comparable Accuracy: After filtering out highly similar false positives, UFX achieved an approximate 60% false alarm rate. While not perfect, this rate is comparable to many existing static bug detection tools designed for the Linux kernel, indicating a reasonable balance between detection power and the burden of false positives.
  • Strategic False Negatives: The tool intentionally introduces some false negatives by choosing to disregard warnings involving challenging constructs like reference counts and recursive data structures. This pragmatic decision prioritizes a more manageable false alarm rate, acknowledging the extreme complexity of precisely modeling these specific patterns in a fully static context.
  • Computational Cost: Analyzing demanding Linux kernel device driver modules with UFX can take over 30 hours. This higher computational expense compared to some existing tools is attributed to the increased complexity of targeting cross-entry issues and the need for comprehensive reasoning across multiple code aspects. Despite the cost, the value of finding critical, otherwise undetectable bugs justifies the investment.

In summary, UFX has proven to be a valuable tool for developers and security practitioners, capable of systematically uncovering intricate cross-entry UAFs that are prevalent and dangerous in large codebases. Its findings contribute significantly to the ongoing effort to enhance the security posture of the Linux kernel.

Technical Deep Dive

▶ Watch: UFX: Per-entry analysis and summarization (4:23)

UFX tackles the complexities of cross-entry UAF detection through a multi-stage static analysis framework, operating on LLVM bitcode. The system is designed to precisely identify alias relationships across different program entry points and then rigorously validate the feasibility of potential UAFs by reasoning about diverse code semantics.

The UFX analysis pipeline consists of several key components:

  1. Inputs:
  • Target Program: The source code compiled into LLVM bitcode, providing a standardized intermediate representation for analysis.
  • Configuration File: A list of all relevant entry functions within the target program. This file can be semi-automatically generated, guiding UFX to the potential starting points for execution paths.
  1. Per-Entry Analysis and Summarization:
  • For each identified entry function, UFX performs an initial, detailed analysis to summarize its effects on pointers and data flow. This summarization is crucial for understanding how objects are allocated, freed, and how their pointers might escape or be modified.
  • The implementation is highly accurate, employing an interprocedure flow, context-sensitive, and even optimistically path-sensitive pre-entry summarization. This means it tracks data flow across function calls, differentiates between different call contexts (e.g., a function called with different arguments), and makes informed assumptions about possible execution paths to generate comprehensive summaries.
  • For instance, for an entry_function_0 that allocates an object, frees it, and then escapes its address to a global pointer GP, the summary would capture these actions: object allocated at Line 1, freed at Line 3, and pointer escaped to GP.
  1. On-Demand Query for Cross-Entry Alias Use-and-Free Pairs:
  • Once per-entry summaries are generated, UFX employs an efficient on-demand query mechanism to identify potential cross-entry UAF candidates.
  • The query process starts from a freed object (e.g., an object freed at Line 3 in entry_function_0).
  • UFX then queries the entry function summaries to determine which global pointers this freed object's address could escape to (e.g., GP).
  • This process is recursively performed. If GP is found to escape to another global pointer GQ in entry_function_1, the query continues.
  • The recursive query eventually leads to an entry function (e.g., entry_function_2) where the aliased object (via GQ) is used or accessed. At this point, a potential cross-entry UAF pair has been identified. This mechanism effectively tracks the "dangling pointer" across multiple, independent execution contexts facilitated by global state.
  1. UF Validation through Unified Partial Order System:
  • Identifying a potential UAF pair is only the first step; UFX must then verify if the UAF can actually happen. This involves collecting all relevant program statements that could influence the UAF's feasibility and encoding their semantics.
  • Collecting Relevant Statements: This includes lock/unlock operations, condition sets and checks, and pointer notifications. Crucially, UFX extends its cross-entry alias analysis to match these statements across different entry functions. For example, it needs to determine if two lock operations in different entry functions operate on the same global lock object or if a condition set in one entry function affects a condition check in another because they operate on the same global variable.
  • Encoding Semantics into a Unified Partial Order System: UFX's innovative approach is to unify diverse code semantics into a system based on partial orders, specifically "happens-before" relationships.
  • Lock/Unlock Semantics: For critical sections protected by locks, UFX encodes the constraint that these sections cannot overlap. If lock_A and lock_B protect critical sections, then either lock_A must happen before lock_B, or lock_B must happen before lock_A. This ensures mutual exclusion.
  • Condition Set/Check Semantics: To trigger a UAF often requires a specific condition to be met or not met. UFX encodes that for the UAF to occur at a specific use site (e.g., Line N), any conflicting condition check (e.g., Line 8) must happen before a condition set (e.g., Line 4) that would invalidate the UAF condition. This captures the timing-dependent nature of many UAFs.
  • Intra-function Constraints: Basic control flow constraints (e.g., Line 1 must execute before Line 2) are also included.
  • SMT Solver Integration: All these encoded constraints are then fed into an SMT (Satisfiability Modulo Theories) solver, such as Z3. If the SMT solver finds a solution – meaning there exists a specific ordering of all relevant program statements that satisfies all the happens-before constraints – then UFX deems the UAF to be feasible. Otherwise, it's considered an infeasible case.

UFX is implemented as a prototype system, building upon a previous tool named "suture" but with significant modifications and enhancements (approximately 12,000 lines of new code). The tool is slated to be fully open-source, allowing other researchers and developers to leverage its capabilities and contribute to its improvement.

Demo / Proof of Concept

▶ Watch: UFX: On-demand query for cross-entry alias pairs (5:40)

While the talk did not feature a live, interactive demonstration in the traditional sense, the effectiveness and practical utility of UFX were thoroughly proven through its rigorous evaluation results. These findings serve as a compelling proof of concept for the tool's capabilities.

UFX's ability to uncover real-world and zero-day vulnerabilities in critical software components like the Linux kernel drivers stands as a testament to its design and implementation. The key demonstrations of its power include:

  • Benchmark Performance: When tested against a dataset of known UAF bugs sourced from the SIS board dashboard, UFX successfully identified significantly more real-world cross-entry UAFs compared to competing static analysis tools. This demonstrated its superior ability to detect complex, distributed UAFs that elude other analyzers.
  • Zero-Day Discovery: The most impactful demonstration was UFX's application to 34 Linux kernel device drivers. This practical deployment led to the successful discovery of 10 independent cross-entry UAF issues. These were previously unknown vulnerabilities, highlighting UFX's capacity to find novel security flaws in widely used and highly scrutinized codebases. The discovery of these zero-days directly validates the tool's core hypothesis: that cross-entry UAFs are prevalent and that a specialized static analyzer can effectively uncover them.
  • Open-Source Availability: The commitment to making UFX fully open source (with a GitHub link provided in the paper) further serves as a "proof of concept" for its reproducibility and future adoption. This allows the security community to inspect its mechanisms, verify its findings, and potentially extend its capabilities to other complex vulnerability types.

These evaluation results, particularly the identification of new, critical vulnerabilities, provide concrete evidence that UFX is a robust and valuable tool for static analysis in the domain of complex Use-After-Free vulnerabilities.

Defensive Implications

▶ Watch: UFX: Encoding code semantics for UAF validation (8:00)

The insights and capabilities offered by UFX have several critical implications for software defenders, developers, and security practitioners, particularly those working with large, multi-entry codebases like operating system kernels:

  1. Proactive Vulnerability Discovery: UFX provides a systematic method for proactively identifying a class of UAFs that are notoriously difficult to find through traditional static analysis or even dynamic fuzzing. Developers can integrate UFX into their continuous integration/continuous deployment (CI/CD) pipelines to catch cross-entry UAFs early in the development lifecycle, significantly reducing the cost and risk associated with post-deployment patching.
  2. Enhanced Code Review Focus: The methodology of UFX highlights the importance of scrutinizing interactions across different entry functions, especially when global state or shared resources are involved. Developers should be particularly wary of scenarios where objects are freed but their pointers might persist in global variables, only to be accessed by a completely separate execution path.
  3. Understanding Complex Interleaving: UFX's approach to modeling lock/unlock mechanisms, condition variables, and pointer notifications as happens-before relationships underscores the need for developers to carefully reason about all possible interleavings of execution paths. Even seemingly robust synchronization mechanisms can fail if the overall system state changes unexpectedly across different entry points.
  4. Adoption of Advanced Static Analysis: The success of UFX demonstrates the necessity of adopting more sophisticated static analysis tools that can handle inter-procedural, context-sensitive, and cross-entry analysis. Relying solely on simpler analyzers will leave critical vulnerability classes undetected. Security teams should evaluate and integrate such advanced tools into their security assessment strategies.
  5. Targeted Fuzzing and Testing: While UFX is a static tool, its findings can inform and guide dynamic testing efforts. The specific UAF candidates identified by UFX, especially those involving complex partial order constraints, can be used to construct highly targeted fuzzing campaigns or test cases, increasing the efficiency of dynamic bug hunting.
  6. Improved Kernel Security Posture: For kernel developers, UFX offers a direct means to improve the security posture of the Linux kernel. The 10 zero-day bugs found in device drivers are a clear indication of the prevalent, yet hidden, nature of these vulnerabilities. Regular application of UFX (or similar tools) can help eliminate these deep-seated flaws, making the kernel more resilient to exploitation.
  7. Contribution to Open Source Security: As UFX is planned to be open source, it provides a valuable resource for the security community. Defenders can contribute to its development, adapt it for other platforms, or use its underlying principles to build custom analysis tools tailored to their specific needs.

In essence, UFX serves as a powerful reminder that security in complex systems requires a holistic understanding of how different components interact, often in non-obvious ways. Its approach equips defenders with the means to systematically uncover these subtle, yet dangerous, vulnerabilities.

Key Takeaways

  • Cross-entry Use-After-Free (UAF) vulnerabilities are prevalent and challenging in large codebases like the Linux kernel, where memory allocation, freeing, and use occur across distinct entry functions.
  • Existing static analyzers often fail to detect these UAFs due to their inability to track complex alias relationships across different entry points and to comprehensively reason about multiple code aspects (locks, conditions, pointer notifications) simultaneously.
  • UFX is a novel static analyzer designed to overcome these limitations by performing precise per-entry function summarization and using an on-demand query to identify cross-entry alias UAF pairs.
  • UFX validates UAF feasibility by encoding diverse code semantics into a unified partial order system and leveraging an SMT solver (Z3) to determine if a specific, exploitable execution path exists.
  • The tool has demonstrated significant success, finding more real-world cross-entry UAFs on benchmarks and discovering 10 independent zero-day UAFs in Linux kernel device drivers.
  • While computationally intensive (up to 30+ hours for some modules) and with a 60% false alarm rate, UFX provides a valuable, systematic approach to finding critical, otherwise undetectable vulnerabilities, contributing significantly to kernel security.

About the Speaker(s)

The talk was presented by Hang Zhang. While his specific title and company were not explicitly detailed in the provided metadata or transcript, the Q&A session indicated his collaboration with researchers from UC Riverside, including co-author Jangha. Hang Zhang's work builds upon previous research, specifically mentioning a prior tool named "suture," which identified data flow bugs across multiple system calls. This current project, UFX, involved significant development, adding approximately 12,000 lines of code to the existing framework, primarily for implementing the new cross-entry alias analysis mechanism and the unified framework for false alarm filtering. His research focuses on advanced static analysis techniques to discover complex vulnerabilities in large software systems, particularly operating system kernels.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid systems-security research with a real contribution: a static analyzer that actually ships findings (10 zero-days in Linux kernel drivers) by solving the cross-entry alias problem that makes existing tools useless for this UAF class. The SMT-backed partial-order feasibility model is the interesting novelty here, and the results justify the approach.

Heather Calloway (CISO) — PASS

Technically serious UAF research with real findings — 10 zero-days in Linux kernel drivers is not nothing. But this is deep static analysis tooling research, and it has no meaningful connection to governance, institutional risk, or defender operations at any level I care about.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025