Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation

Ziyi Guo (PhD student · Northwest University), Kyle Zeng, Xinyu Xing

33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24

Overview

The talk "Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation" by Ziyi Guo, Kyle Zeng, and Xinyu Xing introduces Page Spray, a novel and highly effective page-level memory reuse technique for exploiting vulnerabilities within the Linux kernel. This research illuminates a critical blind spot in current kernel exploitation strategies, which predominantly focus on slab-level object reuse. By demonstrating how attackers can directly reclaim freed kernel pages with arbitrary user-controlled data, Page Spray significantly enhances the exploitability and stability of existing kernel vulnerabilities, particularly those involving use-after-free or double-free conditions.

Watch on YouTube

Visual summary for Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation by Ziyi Guo, Kyle Zeng, Xinyu Xing
Visual summary for Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation by Ziyi Guo, Kyle Zeng, Xinyu Xing

Key moments

  1. 0:00 Introduction to Page Spray in Linux Kernel Exploitation
  2. 0:33 Overview of Linux Kernel Vulnerabilities & Memory Management
  3. 2:29 Discussing State-of-the-Art Heap Exploitation Techniques
  4. 4:40 Introducing Page Spray: Bypassing Slab Allocator for Reclamation
  5. 5:30 Root Causes: Kernel Designs Enabling Page Spray (Page Buffers, Mmap)
  6. 7:11 Practical Exploitation Model of Page Spray with Double Free
  7. 8:50 Evaluation: Exploitability and Stability on 15 Real CVEs
  8. 10:07 Mitigation Strategies: Isolating Page Allocations & SLABVIRTUAL

Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation

Speakers: Ziyi Guo, PhD Student, Northwest University; Kyle Zeng; Xinyu Xing, Arizona State University

Conference: USENIX Security '24

YouTube: https://www.youtube.com/watch?v=wsfi5k37eWI

Overview

The talk "Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation" by Ziyi Guo, Kyle Zeng, and Xinyu Xing introduces Page Spray, a novel and highly effective page-level memory reuse technique for exploiting vulnerabilities within the Linux kernel. This research illuminates a critical blind spot in current kernel exploitation strategies, which predominantly focus on slab-level object reuse. By demonstrating how attackers can directly reclaim freed kernel pages with arbitrary user-controlled data, Page Spray significantly enhances the exploitability and stability of existing kernel vulnerabilities, particularly those involving use-after-free or double-free conditions.

The speakers meticulously detail the underlying kernel design mechanisms that inadvertently enable Page Spray, including specific copy-on-write page-level buffers and the mmap/zero-copy functionality. They present a comprehensive evaluation across 15 real-world CVEs, showcasing the technique's practical applicability on diverse systems, including mobile devices. The work not only provides a deeper understanding of memory reuse in the Linux kernel but also calls for a fundamental rethinking of page allocation and reuse policies to introduce more robust mitigations against such sophisticated attacks.

This research is particularly significant because it pushes the boundaries of kernel exploitation from object-level manipulation to direct page-level control. Traditional kernel exploits often struggle with the precise placement of attacker-controlled data to achieve reliable code execution or privilege escalation. Page Spray offers a more direct and stable path by allowing user-supplied content to directly overlap with critical kernel objects residing on a reclaimed page. Its demonstrated effectiveness and stability across various real-world scenarios make it a crucial topic for both offensive and defensive security researchers operating within the kernel space.

Background

▶ Watch: Introduction to Page Spray in Linux Kernel Exploitation (0:00)

Understanding Page Spray necessitates a foundational grasp of Linux kernel memory management, which broadly relies on two primary allocators: the slab allocator (also known as the heap allocator) and the page allocator. The slab allocator is designed for efficient allocation and deallocation of small, frequently used kernel objects. It groups objects of similar sizes into "slabs," which are themselves composed of one or more contiguous physical memory pages obtained from the page allocator. When a slab is created, pages are allocated for it; when a slab becomes empty and is discarded, its constituent pages are returned to the page allocator.

The page allocator, on the other hand, is the fundamental mechanism for managing physical memory pages (typically 4KB in size) and forms the bedrock of system memory management. Many operations, including slab allocations, directly or indirectly depend on the page allocator. Until now, most advanced Linux kernel exploitation techniques have focused on manipulating the slab allocator to achieve heap-level exploitation.

Two prominent state-of-the-art heap-level exploitation techniques are 30-crate and cross-cache exploitation.

30-crate, as published in CCS and Black Hat USA, is a powerful technique that starts with an object temporal vulnerability (e.g., use-after-free). The attacker maintains a reference to a vulnerable object's slot, frees the object, and then reclaims that same memory slot with a specially crafted, privileged object. This allows the attacker to gain control over critical data structures, such as modifying the passwd file, to achieve privilege escalation.

Cross-cache exploitation extends this by allowing an attacker to transfer a reference from an object in one slab cache (e.g., a normal, user-controlled object) to an object in a different, often dedicated or privileged, slab cache. This typically involves a type confusion where a freed object slot from one cache is reclaimed by an object from another, leading to critical misinterpretations of data.

Both 30-crate and cross-cache exploitation fundamentally rely on the reuse of memory at the slab object level. They aim to control which specific object reclaims a freed slot within a slab. The critical observation made by the researchers is that these techniques ultimately depend on the allocation and freeing of pages for their underlying slab operations. When a slab becomes empty, its pages are eventually freed. Conversely, when a new slab is needed, pages are allocated for it. This constant cycle of page allocation and deallocation for slab management raised a crucial question: Is it possible to bypass the slab allocator entirely and directly reclaim freed pages using the page allocator, rather than waiting for another slab allocation?

The concept of directly interacting with pages for exploitation is not entirely new. The speakers acknowledge that a similar idea was explored approximately nine years ago. However, due to significant increases in system memory and stricter restrictions on address space for user-space processes (especially for mmap operations), those older techniques are largely impractical in modern Linux environments. The modern Page Spray technique presented in this talk addresses these limitations by identifying new mechanisms and practical approaches for page-level memory reuse in contemporary kernels.

Key Findings

▶ Watch: Discussing State-of-the-Art Heap Exploitation Techniques (2:29)

The core finding of this research is the discovery and systematic understanding of Page Spray, a novel page-level memory reuse technique that allows attackers to directly reclaim previously freed kernel pages with arbitrary user-controlled data. This bypasses the typical slab allocator mechanisms, offering a more direct and often more stable path to exploitation. The researchers identified that the root cause of Page Spray lies in specific, often overlooked, design patterns within the Linux kernel that facilitate direct page allocation and user-space interaction with these pages.

The key findings can be summarized as follows:

  1. Page-Level Memory Reuse: Page Spray demonstrates that it is possible to achieve memory reuse at the granularity of a physical memory page, rather than just individual objects within a slab. This means an attacker can overwrite an entire 4KB page (or larger, depending on the page size) with custom data, directly overlapping with critical kernel objects that might still reside on a "freed" page.
  2. Exploiting Kernel Design Patterns: The technique leverages two primary kernel design patterns:
  • Copy-on-Write (CoW) Page-Level Buffers: The kernel employs specific buffers that directly use pages to store massive amounts of data, often in networking or large data transfer operations. These include "rare page-level buffers" and "nonlinear page frag buffers" (used in SKB operations for networking messages). When these buffers are allocated, they directly request pages from the page allocator.
  • Mmap and Zero-Copy Mechanisms: Certain kernel logics allow direct allocation of pages and their subsequent remapping into a user-space process's virtual memory. This mmap functionality, often associated with zero-copy operations, grants user-space processes direct read/write access to these kernel pages. This is crucial for Page Spray, as it enables an attacker to fill the reclaimed kernel page with arbitrary data from user space.
  1. Triggerability via System Calls: The researchers conducted static and dynamic analysis of the kernel codebase and identified multiple call sites related to these CoW and mmap/zero-copy logics. Crucially, all identified vulnerable call sites can be reached and triggered directly through standard system calls from user space, making Page Spray a practical attack vector without requiring complex kernel-mode primitives beyond the initial vulnerability.
  2. Enhanced Exploitability and Stability: The evaluation demonstrated that Page Spray provides comparable, and often superior, exploitability and stability compared to traditional slab-level techniques across a range of real-world vulnerabilities. This improved reliability stems from the direct control over an entire page, reducing the dependency on precise object sizing and race conditions often associated with slab spraying.
  3. Practical Impact: The technique was successfully applied to exploit 15 different real-world CVEs, including those affecting mobile devices (Google Pixel, Samsung) and involving cross-cache operations. This highlights its broad applicability and effectiveness in diverse kernel exploitation scenarios. The researchers also made their exploits publicly available, demonstrating the practical feasibility of the attack.

In essence, Page Spray shifts the paradigm of kernel memory reuse from manipulating individual objects within slabs to directly controlling and overwriting entire kernel pages, opening new avenues for exploitation and demanding a re-evaluation of kernel memory security.

Technical Deep Dive

▶ Watch: Root Causes: Kernel Designs Enabling Page Spray (Page Buffers, Mmap) (5:30)

Page Spray is fundamentally a page-level memory reuse attack that capitalizes on a specific sequence of events involving a vulnerability (like a double-free or use-after-free) and the kernel's page allocation mechanisms. The attack model typically unfolds as follows:

  1. Initial Vulnerability Trigger: An attacker first triggers a memory corruption vulnerability, such as a double-free, on a specific kernel object (the "victim object"). This causes the kernel to believe the object's memory has been freed, even if it hasn't or if it's freed prematurely.
  2. Slab Discard and Page Release: The attacker then orchestrates a situation where the slab containing the victim object is emptied of all other objects. The kernel, perceiving the slab as entirely free (due to the double-free or other manipulations), may decide to discard the entire slab. When a slab is discarded, all the physical memory pages that constituted that slab are returned to the page allocator. Crucially, the victim object's data might still reside on one of these pages, even though the page itself is now marked as free by the page allocator.
  3. Direct Page Allocation (Page Spray): This is the core of Page Spray. Instead of waiting for another slab allocation to reclaim the freed page, the attacker triggers a direct page allocation from user space. The kernel, unaware that a critical object still exists on one of these "freed" pages, allocates such a page for the attacker's request.
  4. User-Controlled Data Injection: The attacker then uses specific kernel mechanisms to write arbitrary data into this newly allocated (and previously freed) page. Because the victim object's data might still be present on this page, the attacker's data effectively overlaps or overwrites the victim object, allowing for control over its structure or contents.

The success of Page Spray heavily relies on identifying and leveraging specific kernel design patterns that allow for direct page allocation and user-space interaction. The researchers highlighted two main categories:

1. Copy-on-Write (CoW) Page-Level Buffers

The Linux kernel, particularly in subsystems dealing with high-throughput data like networking, utilizes buffers that directly allocate and manage memory at the page level. These are often designed for efficiency, avoiding intermediate copies.

  • Rare Page-Level Buffers: These are kernel buffers that directly use entire memory pages to store large amounts of data. The transcript mentions them as being "directly used page buffer for the massive data." When the kernel needs to handle a large block of data, it might request one or more pages from the page allocator rather than allocating smaller chunks from slab caches. If an attacker can trigger the allocation of such a buffer after a vulnerable page has been freed, they can potentially control the contents of that page.
  • Nonlinear Page Frag Buffers (SKB Operations): A prominent example of page-level buffers is found in the networking subsystem, specifically within SKB (Socket Buffer) operations. When a network message is too large to fit into a single linear buffer, the kernel uses "page frag buffers" (page fragment buffers) to store the data across multiple pages. These are referred to as "nonlinear page frag buffers." The sk_buff structure itself can refer to a list of pages (or page fragments) to hold the packet data. If an attacker can trigger the transmission or reception of a large network message, it can lead to the allocation of these page-level buffers, potentially reclaiming a vulnerable page. The crucial aspect here is that the attacker can often control the content of these network messages, which then directly populates the kernel's page-level buffers.

2. Mmap and Zero-Copy Mechanisms

Another critical enabler for Page Spray is the ability to directly map kernel-allocated pages into a user-space process's virtual address space.

  • Direct Page Allocation and Remapping: The kernel provides certain system calls and internal logics that allow it to directly allocate pages from the page allocator and then expose these pages to user space. This is often done for performance reasons, such as in zero-copy operations where data is transferred between kernel and user space without redundant copies. For instance, mmap() can be used by the kernel to map physical pages into a user process's address space.
  • User-Space Access: By leveraging these mmap and zero-copy mechanisms, an attacker gains a user-space virtual address that points directly to the target kernel page. This provides an attacker with a powerful primitive: the ability to read from and write to the kernel page directly from their user-space process. This means after a vulnerable page has been freed and then reclaimed by a direct page allocation triggered by the attacker, the attacker can use the mmap-ed region to fill the entire page with arbitrary, attacker-controlled data. This data then directly overlaps with any critical victim objects that might still reside on that page.

The researchers used both static and dynamic analysis methods to systematically identify and analyze kernel call sites that relate to these page-level allocation and mapping logics. They confirmed that all identified vulnerable call sites could be reached and triggered through standard system calls from user space, making the attack practical and reliable. This ability to directly control page content from user space after a page-level reclaim is what gives Page Spray its significant advantage in terms of exploitability and stability.

Demo / Proof of Concept

▶ Watch: Practical Exploitation Model of Page Spray with Double Free (7:11)

The practical efficacy and robustness of Page Spray were rigorously evaluated through a comprehensive demonstration and proof-of-concept phase. The researchers performed Page Spray exploitation against 15 different real-world CVEs, showcasing its broad applicability and superiority in various scenarios.

The evaluation specifically focused on two key aspects:

  1. Exploitability: The ability of Page Spray to successfully exploit diverse vulnerabilities. The 15 CVEs included a mix of general kernel vulnerabilities, some specifically targeting mobile devices, and others involving cross-cache operations. This diverse set of targets demonstrated that Page Spray is not limited to a narrow class of vulnerabilities but can be adapted to facilitate exploitation where traditional slab-level techniques might struggle or be less reliable.
  • Specific examples highlighted in the talk include exploits developed for vulnerabilities found in Google Pixel and Samsung mobile devices. This underscores the technique's relevance in highly secured modern environments.
  • The research also mentions its application in challenges like Google KCTF (Kernel Capture The Flag) and against specific targets like Typhoon P, further validating its practical utility in competitive and real-world exploitation scenarios.
  • The talk references another presentation from Black Hat USA last year, titled "bad io_uring," which also discussed aspects of Page Spray, indicating a growing recognition of this type of attack.
  1. Stability: The reliability of Page Spray exploitation under varying system conditions. The researchers evaluated its stability under two distinct system workloads: idle and busy. This is a crucial aspect for real-world exploits, as systems rarely operate in perfectly predictable, idle states. The fact that Page Spray demonstrated robust stability even under busy workloads suggests that it is less susceptible to timing issues and memory pressure that can often destabilize slab-level exploits.

To further validate their findings and allow other researchers to reproduce and understand the technique, the team has made their exploits and evaluation results publicly available. A GitHub repository (link provided in the talk, though not explicitly in transcript text) contains the code for the developed exploits, serving as a valuable resource for the security community. The successful exploitation of numerous real-world CVEs, coupled with its demonstrated stability, firmly establishes Page Spray as a potent and practical technique for Linux kernel exploitation.

Defensive Implications

▶ Watch: Mitigation Strategies: Isolating Page Allocations & SLAB_VIRTUAL (10:07)

The discovery and detailed analysis of Page Spray necessitate a fundamental re-evaluation of current Linux kernel memory management and defensive strategies. The core lesson learned is that page-level memory reuse is inherently dangerous and can lead to powerful exploitation primitives if not properly mitigated.

The researchers propose several crucial defensive implications:

  1. Memory Area Isolation for Page Allocation: The most straightforward and effective mitigation strategy involves isolating different memory areas used for page allocation. The idea is to prevent critical kernel objects from residing on pages that could potentially be reclaimed and overwritten by user-controlled data. This can be achieved by:
  • Using Different get_free_pages Flags: The kernel's get_free_pages and related allocation functions accept various flags (e.g., GFP_KERNEL, GFP_USER, GFP_HIGHUSER). By consistently using specific flags to delineate memory regions for different purposes—for instance, allocating pages for critical kernel objects with flags that put them into a distinct memory zone, separate from pages that might be remapped to user space or used for large user-controlled buffers—the kernel can prevent unintended overlaps. Even if a Page Spray attack is triggered, the overlap between critical objects and attacker data would not occur because they would reside in different, isolated memory regions.
  • Dedicated Page Pools: Implementing dedicated page pools for specific types of critical kernel data that are never exposed or directly remapped to user space, nor used for high-volume data transfers that could be attacker-controlled.
  1. Rethinking Page Reuse Design: Beyond flag-based isolation, the research calls for a deeper philosophical shift in how page reuse is designed within the kernel. The current design, which allows pages that previously held critical slab objects to be directly reallocated for user-controlled data, creates the window for Page Spray. Future kernel designs should consider:
  • Strict Page Scrubbing/Zeroing: Ensuring that pages are thoroughly scrubbed (zeroed out) before being reused, especially if they previously held sensitive data or if they are to be remapped to user space. While this can incur a performance overhead, it would prevent information leaks and data overlaps.
  • Delayed Page Release: Introducing mechanisms to delay the reuse of pages that previously held sensitive kernel objects, similar to how some slab allocators might quarantine freed objects.
  • Stronger Type Separation at Page Level: Enhancing the kernel's ability to track the "type" or "sensitivity" of data that resided on a page, and only reusing pages for compatible purposes.
  1. External Mitigation: SLAB_VIRTUAL: The talk also mentions an external mitigation proposed by Google called SLAB_VIRTUAL. While the transcript doesn't detail its mechanics, it's described as "trying to prevent slab virtual address reuse." This suggests a mitigation focused on virtual address randomization or stricter checks to prevent the reuse of virtual addresses associated with freed slab objects, even if the underlying physical page is reclaimed. Although SLAB_VIRTUAL primarily targets slab-level reuse, it complements page-level mitigations by making it harder for attackers to predict or control the virtual addresses of reclaimed memory, thereby complicating the overall exploitation chain.

In summary, defending against Page Spray requires a multi-pronged approach: immediate practical steps like memory area isolation using existing kernel flags, and a long-term re-evaluation of fundamental page reuse policies to introduce more robust and secure memory management paradigms.

Key Takeaways

  • Page Spray is a novel page-level memory reuse technique that allows attackers to directly reclaim freed kernel pages with arbitrary user-controlled data, bypassing traditional slab-level exploitation.
  • The attack leverages specific Linux kernel design patterns, including copy-on-write page-level buffers (e.g., in SKB operations) and mmap/zero-copy mechanisms that allow user-space interaction with kernel pages.
  • Page Spray significantly enhances the exploitability and stability of existing kernel vulnerabilities (like double-free or use-after-free), making them more reliable across diverse system workloads (idle and busy).
  • The technique has been successfully demonstrated on 15 real-world CVEs, including those affecting mobile devices (Google Pixel, Samsung) and in Google KCTF challenges, proving its practical effectiveness.
  • Defenders must rethink page reuse design and implement mitigations such as isolating memory areas for page allocation (e.g., using specific get_free_pages flags) to prevent critical kernel objects from overlapping with attacker-controlled data.
  • The research emphasizes the need for more powerful and comprehensive mitigations within the kernel to address page-level memory reuse, potentially including stricter page scrubbing or external solutions like Google's SLAB_VIRTUAL.

About the Speaker(s)

Ziyi Guo is a PhD student from Northwest University in the computer science department. He is a primary presenter of this research, which represents a joint work between Northwest University and Arizona State University (ASU).

Kyle Zeng is a co-author of the research.

Xinyu Xing is a co-author of the research, affiliated with Arizona State University (ASU).

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research on Page Spray is a critical advancement in Linux kernel exploitation, shifting focus from slab-level to direct page-level control. It's a highly practical technique, demonstrated against real-world CVEs, that fundamentally redefines memory reuse for both attackers and defenders. Anyone serious about kernel security needs to understand this.

Heather Calloway (CISO) — STRONG ACCEPT

This research on Page Spray fundamentally shifts our understanding of Linux kernel exploitation, moving beyond slab-level to direct page-level control. It exposes critical gaps in kernel memory reuse policies, demonstrating a stable path to full system compromise. The findings demand a re-evaluation of kernel design and memory allocation strategies to ensure robust isolation and prevent this class of attack.

→ Top-rated talks at 33rd USENIX Security Symposium

All talks from 33rd USENIX Security Symposium