Check It Again: Detecting Lacking-Recheck Bugs in OS Kernels

Опубликовано: 02 Ноябрь 2024
на канале: Association for Computing Machinery (ACM)
223
2

Security-checked variables are often subject to modification after the check. If a recheck is lacking after a modification, security issues may arise, e.g., adversaries can control the checked variable to launch critical attacks such as out-of-bound memory access or privilege escalation. We call such cases lacking-recheck (LRC) bugs, a subclass of TOCTTOU bugs, which have not been explored yet.
Read this paper in the ACM Digital Library: https://dl.acm.org/citation.cfm?id=32...