Await() a Second: Evading Control Flow Integrity by Hijacking C++ Coroutines
Marcos Bajo
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · System Security 4: Kernel and Low-Level System Security
Overview
This groundbreaking research paper, "Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts," systematically investigates the widespread prevalence and severe security implications of misconfigured or insecure tunnelling hosts across the IPv4 and IPv6 Internet. Presented by Angelos Beitis and Mathy Vanhoef from KU Leuven, the work uncovers a startling number of vulnerable hosts—over 4 million—that accept unauthenticated tunnelling traffic from any source. These hosts, often running legacy or modern tunnelling protocols without proper security mechanisms, present significant risks, ranging from enabling source address spoofing and acting as one-way proxies to facilitating access to private networks.
Read the paper · Download the PDF (PDF) · Slides
Paper abstract
This paper studies the prevalence and security impact of open tunnelling hosts on the Internet. These hosts accept legacy or modern tunnelling traffic from any source. We first scan the Internet for vulnerable IPv4 and IPv6 hosts, using 7 different scan methods, revealing more than 4 million vulnerable hosts which accept unauthenticated IP in IP (IPIP), Generic Routing Encapsulation (GRE), IPv4 in IPv6 (4in6), or IPv6 in IPv4 (6in4) traffic. These hosts can be abused as one-way proxies, can enable an adversary to spoof the source address of packets, or can permit access to an organization's private network. The discovered hosts also facilitate new Denial-of-service (DoS) attacks. Two new DoS attacks amplify traffic: one concentrates traffic in time, and another loops packets between vulnerable hosts, resulting in an amplification factor of at least 16 and 75, respectively. Additionally, we present an Economic Denial of Sustainability (EDoS) attack, where the outgoing bandwidth of a host is drained. Finally, we discuss countermeasures and hope our findings will motivate people to better secure tunnelling hosts.

Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts
Speakers: Angelos Beitis, Researcher, KU Leuven; Mathy Vanhoef, Professor, KU Leuven; DistriNet, KU Leuven
Conference: USENIX Security
Overview
This groundbreaking research paper, "Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts," systematically investigates the widespread prevalence and severe security implications of misconfigured or insecure tunnelling hosts across the IPv4 and IPv6 Internet. Presented by Angelos Beitis and Mathy Vanhoef from KU Leuven, the work uncovers a startling number of vulnerable hosts—over 4 million—that accept unauthenticated tunnelling traffic from any source. These hosts, often running legacy or modern tunnelling protocols without proper security mechanisms, present significant risks, ranging from enabling source address spoofing and acting as one-way proxies to facilitating access to private networks.
The paper goes beyond mere discovery, detailing novel and potent Denial-of-Service (DoS) attacks that leverage these vulnerabilities. These include the Ping-Pong amplification attack, which loops packets between vulnerable hosts for significant traffic amplification, and the Tunnelled-Temporal Lensing (TuTL) attack, designed to concentrate traffic in time for a devastating burst. Additionally, an Economic Denial of Sustainability (EDoS) attack is presented, exploiting the outbound bandwidth consumption of cloud-hosted vulnerable systems. This research is critical for network administrators, cloud providers, and security professionals, highlighting a pervasive and often overlooked class of vulnerabilities that demand immediate attention and robust defensive strategies.
Background
Tunnelling protocols are fundamental to modern internet infrastructure, enabling disparate networks to communicate and forming the basis for Virtual Private Networks (VPNs). Protocols such as IP in IP (IPIP) (RFC 2003), Generic Routing Encapsulation (GRE) (RFC 2784), IPv4 in IPv6 (4in6) (RFC 4213), and IPv6 in IPv4 (6in4) (RFC 2473) encapsulate one type of network packet within another, forwarding it to a destination that then decapsulates and processes the inner packet. While essential, a critical limitation of many of these protocols is their inherent lack of authentication or encryption. To ensure security, they are typically designed to be used in conjunction with protocols like Internet Protocol Security (IPsec) (RFC 53).
Unfortunately, as previous work by Yannay (2020) demonstrated for IPv4 IPIP hosts, these tunnelling protocols are frequently deployed without the necessary additional security layers. This creates vulnerable hosts that accept plaintext tunnelling traffic from arbitrary sources, allowing attackers to inject traffic into tunnels or even spoof source IP addresses. Yannay's initial discovery of 150,000 vulnerable IPIP hosts highlighted a significant gap in Internet security, but left several questions unanswered: whether IPv6 hosts were similarly vulnerable, how to best scan for such vulnerabilities, if other tunnelling protocols were affected, the full scope of security implications, and practical defenses.
This paper systematically addresses these questions by analyzing a broader range of tunnelling protocols, including IPIP, GRE, IP6IP6 (IPv6 in IPv6, RFC 2473), Generic UDP Encapsulation (GUE) (a draft standard), 4in6, and 6in4. It builds upon the concept of temporal lensing attacks, first introduced by Rasti et al., which achieve a Denial-of-Service effect by concentrating packets in time rather than solely amplifying their volume. The core problem lies in the misconfiguration of tunnelling interfaces, particularly in Linux systems, where the remote address field is often left empty (allowing decapsulation from any source) and the accept_local variable is set to True (allowing the forwarding of inner packets with the host's own address as the source), thereby turning a legitimate tunnelling endpoint into an open, unauthenticated proxy.
Key Findings
The research uncovered a staggering scale of vulnerability, identifying 4,263,193 vulnerable tunnelling hosts across the Internet. Specifically, 3,527,565 vulnerable IPv4 hosts and 735,628 vulnerable IPv6 hosts were detected through a comprehensive scanning methodology involving 7 distinct scan methods. This significantly expands upon prior work, revealing that all studied tunnelling protocols (IPIP, GRE, IP6IP6, 4in6, 6in4) can be vulnerable. GUE, though supported by Linux, did not yield any vulnerable hosts in extensive scans.
A critical finding is the prevalence of spoofing-capable hosts: over 1,858,892 hosts were identified that could be abused to completely spoof their source IP address. This undermines traditional network filtering assumptions and enables a wide array of attacks. China stands out, hosting approximately 59% of all identified spoofing-capable hosts, with AS Chinanet (CHN) alone accounting for about 24%. In total, 4,276 Autonomous Systems (ASs) from 173 countries contained hosts capable of spoofing, indicating a systemic failure in source address filtering across a significant portion of the Internet.
The paper also introduces three novel Denial-of-Service (DoS) attacks:
- Ping-Pong amplification attack: Achieves an amplification factor of at least 75 (for 3000-byte IPIP packets) by recursively encapsulating tunnelling packets and looping them between two vulnerable hosts. Theoretically, amplification factors could reach 1638 for IPv4 and 819 for IPv6 under ideal MTU conditions. This attack also enables an Economic Denial of Sustainability (EDoS) attack by draining a cloud-hosted victim's outgoing bandwidth.
- Tunnelled-Temporal Lensing (TuTL) attack: Leverages chains of vulnerable tunnelling hosts to create paths with varying latencies, allowing an attacker to schedule packet bursts to arrive simultaneously at a victim. Experimental results showed an average amplification factor of 16 using just five vulnerable IP6IP6 hosts, demonstrating its potency even with limited resources.
- Administrative DoS attack: Exploits the ability to spoof malicious traffic from a victim's IP address towards organizations known for sending abuse reports, potentially leading to the victim's account suspension or IP blocklisting.
The study also disclosed specific vulnerabilities, which have been assigned CVE-2024-7596 (affecting GRE and GRE6), CVE-2024-7595 (affecting GUE, though no vulnerable hosts were found), CVE-2025-23018 (affecting 4in6 and IP6IP6), and CVE-2025-23019 (affecting 6in4). This formal recognition underscores the severity and widespread nature of these misconfigurations.
Technical Deep Dive
The core of this research lies in its systematic approach to discovering vulnerable tunnelling hosts, employing seven distinct scanning methods across various tunnelling protocols. The authors selected protocols (IPIP, GRE, GUE, 4in6, 6in4, IP6IP6) based on their lack of default authentication/encryption and support in recent Linux kernels. Preliminary local experiments confirmed that all selected protocols (except GUE, for which no vulnerable Internet hosts were found) could be configured to accept unauthenticated traffic from arbitrary sources.
The vulnerability in Linux hosts typically arises from two factors:
- Decapsulating Arbitrary Traffic: The
remote addressfield when setting up a tunnelling interface can be left empty, causing the host to decapsulate and serve packets from any source address. For GRE, this effectively creates a multipoint GRE (mGRE) tunnel. - Forwarding Traffic with Source IP: The Linux kernel, by default, prevents forwarding packets whose source address is that of its own interface. However, setting the
accept_localvariable toTruebypasses this, allowing encapsulated headers with the vulnerable host's address as the source to be forwarded. If the network also has poor filtering, an attacker can spoof arbitrary source addresses.
The scanning methodology utilized ZMap for IPv4 and ZMapv6 with an IPv6 hitlist for IPv6 addresses. Scans were conducted from AWS and Time4VPS instances. The 7 scan methods fall into three categories:
- Standard Tunnel Scans:
- Standard Scan: Sends a probe with the inner packet's source address set to the potentially vulnerable host's address. If the host decapsulates and forwards this, the scanner receives the inner packet. This allows the forwarded traffic to bypass potential source address filtering.
- Subnet-Spoofing Scan: Similar to the standard scan, but the inner packet's source IP is in the same subnet as the host. This helps detect hosts that might filter arbitrary spoofed addresses but still forward packets from their local subnet due to less stringent internal filtering.
- Spoofing Scan: The inner packet's source IP is an arbitrary, spoofed address (e.g.,
100.200.a.b). A reply indicates the host's network has poor egress filtering, allowing the host to be abused for arbitrary IP spoofing. - 6to4 & IPv4-Mapped Address Scan: Specifically for 6in4 and 4in6, where the IPv6 address of a host isn't known when probing via its IPv4 address. The inner IPv6 packet's source address is set to the host's 6to4 or IPv4-mapped address (e.g.,
2002:a.b.c.d::or::ffff:a.b.c.d). These are derived from the host's outer IPv4 address, providing a valid IPv6 source that is less likely to be filtered.
- Tunnelled ICMP Echo/Reply Scan: The inner packet is an ICMP Echo request destined for the vulnerable host itself. If the host is vulnerable and replies to ICMP, it will send an ICMP Echo reply back to the scanner. This detects vulnerable hosts that might not forward inner packets to external destinations.
- Tunnelled ICMP TTL Expired Scan: The inner IPv4 header has a TTL (Time to Live) of 1, or an IPv6 header has a hop limit of 0. The inner packet's destination is not the host itself. A vulnerable host decapsulates the outer header, processes the inner header, finds its TTL/hop limit expired, and sends an ICMP TTL Expired message back to the inner packet's source (the scanner). This method helps discover hosts behind NAT or those that do not reply to Echo requests, including some Virtual Private Cloud (VPC) instances that may only allow outgoing packets with a source address matching the instance's private IP.
Ethical considerations were paramount during the scanning process. Scanning rates were limited to 10-20MBs (IPv4 scans taking ~4 days), and IPv6 scans were conducted once daily. Probes used benign ICMP packets, and spoofed ICMP Echo replies were carefully constructed to minimize negative impact. The authors hosted a website with scan information and offered an opt-out mechanism. Disclosure was made to CERT/CC, the Shadowserver Foundation, and national CERTs, with CVEs assigned to the discovered vulnerabilities.
Analysis of open ports and domains on vulnerable hosts revealed interesting patterns: GRE hosts commonly had BGP (port 179), GTP-C (port 2123), and GTP-U (port 2152) open, suggesting they are often routers or part of mobile networks. IPIP and IP6IP6 hosts frequently had HTTP (port 80), HTTPS (port 443), and SNMP (port 161/162) open, indicating many are likely servers, including a significant presence within Facebook's CDN (fbcdn). 6in4 and 4in6 hosts showed high prevalence of NTP (port 123) and SNMP, suggesting they are often routers.
Demo / Proof of Concept
While no live "demo" was conducted in the traditional conference talk sense due to ethical constraints, the paper rigorously describes and, in some cases, experimentally validates several powerful attack vectors enabled by these vulnerable tunnelling hosts. These attacks serve as concrete proofs of concept for the security implications.
One observed vulnerability during testing was an IPv6 looping bug in Linux for 6in4 packets: an IPv6 packet with a destination address of ::IPV4_ADDRESS_IN_HEX caused the Linux kernel to loop the packet on the tunnelling interface 256 times until the hop limit expired, resulting in a trivial DoS.
The paper then details three novel DoS attacks:
- Administrative DoS Attack (Abusing Abuse Reports): This attack leverages the ability of spoofing-capable hosts to send malicious traffic that appears to originate from a victim. An attacker can direct spoofed malicious traffic (e.g., port scans, suspicious requests) towards organizations known for generating quick abuse reports. If a victim's IP address is used as the spoofed source, the victim's hosting provider could receive a flood of abuse reports, leading to administrative overhead, temporary account suspension, or even permanent termination. While not tested in practice due to ethical concerns, the observed rapid generation of abuse reports during the authors' own scanning activities validates the feasibility of this attack.
- Ping-Pong Amplification Attack: This is a novel traffic amplification DoS attack. An attacker constructs a packet with multiple nested tunnelling headers (e.g., IPIP within IPIP). The inner headers are crafted such that the destination of one inner packet is a second vulnerable host, and the destination of the next inner packet is the first vulnerable host, creating a "ping-pong" loop. The attacker sends this recursively encapsulated packet to one of the vulnerable hosts. Each host in the loop decapsulates a header and forwards the remaining (smaller) packet to the next host. This continues until all headers are stripped or the packet's Maximum Transmission Unit (MTU) is reached.
- Amplification: The attack amplifies the amount of bytes-per-second sent by the attacker. For an IPIP packet of 1500 bytes, containing 75 headers (assuming 20 bytes per IP header), the total traffic caused to the first victim is 56,250 bytes, yielding an amplification factor of 37.5. For a 3000-byte IPIP packet, the amplification factor can reach 75. Theoretically, with an MTU of 65,520 bytes, the amplification factor could be 1638 for IPv4 and 819 for IPv6. This attack is particularly concerning for cloud-hosted vulnerable systems, as the extensive outbound traffic generated can lead to an Economic Denial of Sustainability (EDoS) attack, incurring significant financial costs for the victim.
- Tunnelled-Temporal Lensing (TuTL) Attack: This attack generates a concentrated burst of traffic (a "pulse") at a victim by exploiting differing latencies through chains of vulnerable hosts.
- Phases:
- Latency Collection: The attacker first measures latencies between itself and vulnerable hosts, between vulnerable hosts, and between vulnerable hosts and the victim. This is done by sending tunnelled probes and measuring RTTs (e.g.,
M → A → Mfor attacker-to-host latencyα, orM → A → B → Mfor host-to-host latencyβ). - Path Exploration: Using a Breadth-First Search (BFS) algorithm, the attacker constructs multiple unique paths (chains of vulnerable hosts) towards the victim, ensuring each path introduces a significant variance in total latency (e.g., a 10ms threshold). Paths are prioritized by depth, and a limit is placed on the traffic processed by any single intermediate host to prevent its overload.
- Path & Traffic Scheduling: Paths are sorted by latency. The attacker calculates "switch times" (
st_i = ℓ_i - ℓ_{i+1}) – the precise moments to switch from sending packet bursts over a longer-latency path to a shorter-latency path. By carefully scheduling these bursts, all packets arrive simultaneously at the victim, creating a high-volume, short-duration traffic pulse. - Experimental Results: Due to ethical concerns, this attack was tested using five self-controlled vulnerable IP6IP6 hosts across diverse geographical locations (US, France, Singapore). With packets limited to 1280 bytes, the experiments demonstrated an average amplification factor of 11 with two hosts, increasing to 16 with five hosts. The results visually confirm the "pulsing window" effect, where the victim receives a significant peak of inbound traffic within a very short timeframe (e.g., 20ms). This amplification factor is comparable to or exceeds that of other temporal lensing attacks, even with a limited number of controlled hosts.
Defensive Implications
The findings of this paper highlight a critical need for enhanced security measures for tunnelling hosts, categorizable into host-level and network-level defenses.
Host Defences
Administrators of individual hosts running tunnelling protocols should implement the following:
- Restrict Tunnelling Sources: Configure tunnelling interfaces to accept packets only from trusted or explicitly known source IP addresses. For multi-point GRE (mGRE) or similar setups where the
remote addressfield is left empty, firewall rules should be implemented to drop encapsulated packets originating from non-trusted sources. This prevents the host from acting as an open proxy and mitigates the risk of being discovered by Internet-wide scans. - Utilize GRE Keys (with caution): While not a strong authentication mechanism, using a non-default GRE key can make it harder for casual adversaries or man-on-the-side attackers to construct valid GRE packets. However, keys are unencrypted and can be trivially eavesdropped or brute-forced if explicitly targeted.
- Implement IPsec: The most robust host defense is to combine tunnelling protocols with IPsec. IPsec provides strong authentication and encryption, ensuring that only legitimate and authorized traffic is decapsulated and processed. Hosts should be configured to accept tunnelling packets only if they are protected by IPsec. This protects against injection, spoofing, and DoS attacks.
- Disable
accept_local(if not strictly needed): The Linux kernel'saccept_localvariable, if set toTrue, allows forwarding of inner packets with the host's own address as the source. Disabling this (if not required for specific applications) can prevent the host from being abused for source address spoofing, especially in networks with poor egress filtering.
Network Defences
Network operators and Autonomous Systems (ASs) play a crucial role in mitigating these vulnerabilities:
- Implement Source Address Filtering (BCP 38/RFC 2827 & RFC 3704): A staggering number of ASs (over 4,000) were found to have inadequate source address filtering, enabling source IP spoofing. Networks must rigorously implement ingress and egress filtering to ensure that outgoing packets genuinely originate from within their allocated IP space and that incoming packets have valid source addresses for their network. This is the most effective defense against spoofing-capable hosts and the administrative DoS attack.
- Deep Packet Inspection (DPI) for Tunnelling Traffic: Networks can employ DPI to detect and drop potentially malicious tunnelling packets.
- Nested Tunnels: Packets with an unusually high number of recursively encapsulated headers (e.g., exceeding a predefined threshold
x, wherexis the expected maximum number of tunnelled hosts within the network) are highly suspicious and should be dropped. This directly counters the Ping-Pong amplification attack. - Malicious Inner Packet Characteristics: DPI can also inspect inner packet characteristics. For instance, inner packets with a TTL (Time to Live) of 0 are indicative of malicious intent (used by attackers for discovery) and should be dropped.
- Block Unencrypted Tunnelling Protocols: If a network or host is intended to use IPsec for secure tunnelling, but is also misconfigured to accept unencrypted tunnelling packets, network-level firewalls can be configured to block all unencrypted tunnelling traffic. This allows legitimate IPsec-protected tunnels to function normally while preventing attacks exploiting the unencrypted channel.
By adopting these comprehensive host and network defenses, organizations can significantly reduce their exposure to the threats posed by vulnerable tunnelling hosts and the novel DoS attacks described in this paper.
Key Takeaways
- Widespread Vulnerability: Over 4 million IPv4 and IPv6 hosts across the Internet are vulnerable to unauthenticated tunnelling, accepting traffic from any source via protocols like IPIP, GRE, 4in6, and 6in4.
- Systemic Spoofing Capability: A significant portion of these hosts (over 1.8 million) and over 4,000 Autonomous Systems can be abused to spoof arbitrary source IP addresses, fundamentally undermining network security assumptions.
- Novel DoS Attacks: The research introduces potent new DoS attacks: the Ping-Pong amplification attack (amplification factor of at least 75), the Tunnelled-Temporal Lensing (TuTL) attack (amplification factor of at least 16), and an Economic Denial of Sustainability (EDoS) attack.
- Critical Misconfigurations: Vulnerabilities often stem from misconfigured Linux tunnelling interfaces that allow decapsulation from arbitrary sources and forwarding of self-sourced inner packets.
- Urgent Need for Defenses: Both host-level (e.g., using IPsec, restricting sources) and network-level (e.g., rigorous ingress/egress filtering, deep packet inspection for nested tunnels or TTL=0) defenses are urgently needed to mitigate these widespread threats.
- CVEs Assigned: The discovered vulnerabilities have been assigned CVEs (CVE-2024-7596, CVE-2024-7595, CVE-2025-23018, CVE-2025-23019), underscoring their severity and the need for immediate action.
About the Speaker(s)
The research was conducted by Angelos Beitis and Mathy Vanhoef, affiliated with KU Leuven and its DistriNet research group. Angelos Beitis is a researcher whose work focuses on network security, particularly the discovery and exploitation of internet-wide vulnerabilities in fundamental protocols. Mathy Vanhoef is a professor at KU Leuven, known for his significant contributions to network security research, including past discoveries in Wi-Fi security. Their collaborative efforts at DistriNet (Distributed Systems and Networks) at KU Leuven aim to identify and address critical security flaws in widely deployed network technologies, motivating better security practices across the Internet.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This is what real Internet security research looks like. Beitis and Vanhoef didn't just find a vulnerability — they systematically mapped 4+ million vulnerable tunnelling hosts across the entire IPv4/IPv6 address space, then weaponized the findings into three novel DoS attacks with measured amplification factors. The Ping-Pong and TuTL attacks are genuinely clever, the scanning methodology is rigorous, and the CVEs are already assigned.
Heather Calloway (CISO) — SOLID
Solid security research with real operational implications. 4.2 million vulnerable hosts capable of spoofing and amplification attacks is a number that belongs in your next infrastructure risk assessment. The tunnelling protocol misconfiguration problem is systemic, affects major cloud and mobile network infrastructure, and the novel DoS techniques are practical.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)