By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New Linux Kernel Exploit Technique ‘SLUBStick’ Discovered by Researchers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New Linux Kernel Exploit Technique ‘SLUBStick’ Discovered by Researchers
Tech News

New Linux Kernel Exploit Technique ‘SLUBStick’ Discovered by Researchers

By Viral Trending Content 2 Min Read
Share
SHARE

Aug 07, 2024Ravie LakshmananLinux / Vulnerability

Linux Kernel Exploit

Cybersecurity researchers have shed light on a novel Linux kernel exploitation technique dubbed SLUBStick that could be exploited to elevate a limited heap vulnerability to an arbitrary memory read-and-write primitive.

“Initially, it exploits a timing side-channel of the allocator to perform a cross-cache attack reliably,” a group of academics from the Graz University of Technology said [PDF]. “Concretely, exploiting the side-channel leakage pushes the success rate to above 99% for frequently used generic caches.”

Memory safety vulnerabilities impacting the Linux kernel have limited capabilities and are a lot more challenging to exploit owing to security features like Supervisor Mode Access Prevention (SMAP), Kernel address space layout randomization (KASLR), and kernel control flow integrity (kCFI).

Cybersecurity

While software cross-cache attacks have been devised as a way to counter kernel hardening strategies like coarse-grained heap separation, studies have shown that existing methods only have a success rate of only 40%.

SLUBStick has been demonstrated on versions 5.19 and 6.2 of the Linux kernel using nine security flaws (e.g., double free, use-after-free, and out-of-bounds write) discovered between 2021 and 2023, leading to privilege escalation to root with no authentication and container escapes.

The core idea behind the approach is to offer the ability to modify kernel data and obtain an arbitrary memory read-and- write primitive in a manner that reliably surmounts existing defences like KASLR.

However for this to work, the threat model assumes the presence of a heap vulnerability in the Linux kernel and that an unprivileged user has code execution capabilities.

“SLUBStick exploits more recent systems, including v5.19 and v6.2, for a wide variety of heap vulnerabilities,” the researchers said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

California Suspends Enforcement of Law Requiring VCs to Report Diversity Data

Irish drone delivery firm Manna confirms $50m raise, plans 400 new jobs

Sky TV: 3 thriller series I can’t wait to see

Galaxy Watch Blood Pressure Monitoring Launches in the U.S.

8 of the company’s biggest tech milestones

TAGGED: Cyber Security, Cybersecurity, Internet, Linux, Linux Kernel, privilege escalation, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Denver affordable housing sales tax moves closer to ballot — here is what’s changed
Next Article Plus Token Ponzi scheme wallets moved $63M ETH after years of inactivity
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Switzerland eyes dropping purchase of US Patriot air defence system over delivery delays
World News
Is This The Beginning Of The End For Bitcoin Treasury Companies? Here’s what You Should Know
Crypto
Map: 7.4-Magnitude Earthquake in Indonesia Raises Tsunami Alerts
World News
MindsEye Developer Looking to Name And Shame Alleged Saboteurs In Blacklist Update
Gaming News
MTG's Avatar Collector Booster boxes are currently $100 off on Amazon
Gaming News
This UK ‘fish and chip train’ blends nostalgia, delicious treats and sunny seaside vibes
Travel
California Suspends Enforcement of Law Requiring VCs to Report Diversity Data
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?