New Linux Kernel Exploit Technique 'SLUBStick' Discovered by Researchers

New SLUBStick exploit increases success rate of Linux kernel attacks to 99%, bypassing security defenses in versions 5.19 and 6.2.

The Hacker News

Researchers unveil #SLUBStick, a new #Linux kernel exploit technique with a 99% success rate, bypassing security measures and escalating privileges.

https://thehackernews.com/2024/08/new-linux-kernel-exploit-technique.html

#cybersecurity #hacking #infosec

New Linux Kernel Exploit Technique 'SLUBStick' Discovered by Researchers

New SLUBStick exploit increases success rate of Linux kernel attacks to 99%, bypassing security defenses in versions 5.19 and 6.2.

The Hacker News

#Linux #カーネル が新しい #SLUBStick #クロスキャッシュ #攻撃 の影響を受ける 」: #BLEEPINGCOMPUTE

「SLUBStick と呼ばれる新しい Linux カーネル クロスキャッシュ攻撃は、限定的なヒープの脆弱性を任意のメモリの読み書き機能に変換することに 99% 成功しており、研究者は特権を昇格したり、コンテナから逃れたりすることができます。 」

https://www.bleepingcomputer.com/news/security/linux-kernel-impacted-by-new-slubstick-cross-cache-attack/

#prattohome #BLEEPINGCOMPUTE

Linux kernel impacted by new SLUBStick cross-cache attack

A novel Linux Kernel cross-cache attack named SLUBStick has a 99% success in converting a limited heap vulnerability into an arbitrary memory read-and-write capability, letting the researchers elevate privileges or escape containers.

BleepingComputer
Linux kernel impacted by new SLUBStick cross-cache attack

A novel Linux Kernel cross-cache attack named SLUBStick has a 99% success in converting a limited heap vulnerability into an arbitrary memory read-and-write capability, letting the researchers elevate privileges or escape containers.

BleepingComputer

I had the pleasure to contribute to Lukas Maar's #USENIX2024 paper "SLUBStick".
SLUBStick elevates limited heap vulnerabilities within the #Linux kernel to arbitrary memory read-and-write primitives, leveraging a timing side channel.
Thanks to Lukas Maar, Martin Unterguggenberger, Mathias Oberhuber and Stefan Mangard for this great opportunity!
Congratulations to Lukas Maar for driving the paper to acceptance at USENIX Security!

You can read the full paper here: https://stefangast.eu/papers/slubstick.pdf

#SLUBStick #Kernel #Linux #KernelSecurity #sidechannel #usenixsecurity #usenixsec