In brief
- This batch covers privilege escalation pathways in the Linux kernel via Data-Oriented Programming and through developer-reserved syscall interfaces in VMware ESXi.
- A standards-driven methodology effectively identified IMSI-catchers in the wild by characterizing specific causal messages rather than relying on correlated behavioral anomalies.
Demystifying the Access Control Mechanism of ESXi VMKernel
- VMware ESXi uses a proprietary, closed-source mandatory access control mechanism in its VMKernel to enforce privilege isolation and sandbox restrictions.
- By developing a domain-control structure oriented analysis method and a structure-aware debugging framework, researchers reconstructed VMKernel’s internal permission logic.
- They uncovered 14 vulnerabilities, including writable in-memory control structures and developer-reserved syscall interfaces, allowing attackers to bypass sandbox restrictions and escalate privileges.
Liu, Y. et al. “Demystifying the Access Control Mechanism of ESXi VMKernel.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/demystifying-the-access-control-mechanism-of-esxi-vmkernel/
Detecting IMSI-Catchers by Characterizing Identity Exposing Messages in Cellular Traffic
- Prior IMSI-catcher detection tools have focused on correlated behaviors like ephemeral base stations or weak ciphers, leading to high false-positive rates during benign network changes.
- This paper introduces a standards-driven methodology that identifies 53 specific messages an adversary can use to force an IMSI exposure, focusing on causal attributes rather than correlated anomalies.
- By establishing a baseline ratio of these messages through a two-continent measurement study, the approach detected anomalous behavior at a large-scale public event with statistical significance ($p \ll 0.005$).
Tucker, T. et al. “Detecting IMSI-Catchers by Characterizing Identity Exposing Messages in Cellular Traffic.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/detecting-imsi-catchers-by-characterizing-identity-exposing-messages-in-cellular-traffic/
DirtyFree: Simplified Data-Oriented Programming in the Linux Kernel
- As Kernel Control-Flow Integrity (KCFI) mitigates return-oriented programming (ROP) attacks, Data-Oriented Programming (DOP) has become a primary alternative for privilege escalation.
- Traditional DOP attacks are complex and multistaged, but this paper introduces DIRTYFREE, a systematic method that uses an arbitrary free primitive to force deallocation of attacker-controlled kernel objects.
- The technique successfully exploited 24 real-world kernel vulnerabilities, and the authors also propose two mitigations that prevent exploitation with negligible performance overhead.
Lee, Y. et al. “DirtyFree: Simplified Data-Oriented Programming in the Linux Kernel.” NDSS 2026. https://www.ndss-symposium.org/ndss-paper/dirtyfree-simplified-data-oriented-programming-in-the-linux-kernel/