#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
About this talk
In this talk, Lukas Maar discusses two timing side-channel attacks that derandomize the locations of security-critical kernel objects within the latest Linux kernel. The first attack focuses on kernel hash tables, exploiting timing differences to disclose memory layout information, marking it as the first of its kind on the Linux kernel. The second attack targets the Translation Lookaside Buffer (TLB), utilizing TLB leakage along with precise kernel memory manipulation to uncover the locations of vital kernel objects such as heap allocations and page tables. The speaker offers a detailed root cause analysis of both attacks, revealing how specific kernel design and defense mechanisms inadvertently facilitate these vulnerabilities, ultimately demonstrating an end-to-end attack that allows an unprivileged user to leak locations of critical kernel objects on an updated Ubuntu Linux system.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03
#NullconBerlin2025 | Finding Bugs in V8: A Formal Verification Approach by Simon Gerst
36:58