In brief

  • Side-channel research advances with new page cache attacks on fully up-to-date Linux kernels and cross-VM TLB attacks targeting virtualized NVIDIA GPUs in cloud environments.
  • Web application security testing is improved with evolutionary search to navigate complex constraints in application state and input formats.

Eviction Notice: Reviving and Advancing Page Cache Attacks

  • Introduces a systematic approach to page cache attacks based on four primitives: flush, reload, evict, and monitor, deriving five generic attack techniques.

  • The attacks operate on fully up-to-date Linux kernels and bypass existing mitigations that were deployed since 2019.

  • The fastest attack (Flush+Monitor) achieves an average capacity of 37.7 kB/s in a cross-process covert channel, and low-frequency attacks demonstrate inter-keystroke timing detection with a spatial resolution of 4 kB and temporal resolution of 0.8 µs.

  • Neela, S. R., Juffinger, J., Maar, L., Gruss, D. “Eviction Notice: Reviving and Advancing Page Cache Attacks.” NDSS 2026 — https://www.ndss-symposium.org/ndss-paper/eviction-notice-reviving-and-advancing-page-cache-attacks/

Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel Attacks

  • Presents the first investigation into potential information leakage through microarchitectural components in virtualized NVIDIA GPUs, which are widely deployed in cloud environments like Desktop-as-a-Service (DaaS).

  • The attack exploits the translation lookaside buffers (TLBs) in these virtualized GPUs to mount cross-VM side-channel attacks.

  • A Prime+Probe attack primitive is tailored specifically to the GPU’s TLB, overcoming constraints in the NVIDIA vGPU runtime that restrict CUDA applications to allocating memory only in 2 MB pages.

  • Jin, H., Guo, Y., Zhang, Z. “Exploiting TLBs in Virtualized GPUs for Cross-VM Side-Channel Attacks.” NDSS 2026 — https://www.ndss-symposium.org/ndss-paper/exploiting-tlbs-in-virtualized-gpus-for-cross-vm-side-channel-attacks/

  • Addresses the limitations of previous vulnerability scanners that naively explore application state without satisfying input format constraints and constraints between web page elements.

  • The tool, EvoCrawl, uses evolutionary search to efficiently find different sequences of web interactions that can successfully submit inputs to web applications.

  • In evaluations, EvoCrawl achieved a 59% increase in code coverage and successfully submitted HTML forms 5 times more frequently than the next best tool, finding eight zero-day vulnerabilities in applications like WordPress and GitLab.

  • Guo, X., Kawlay, A., Liu, E., Lie, D. “EvoCrawl: Exploring Web Application Code and State using Evolutionary Search.” NDSS 2026 — https://www.ndss-symposium.org/ndss-paper/evocrawl-exploring-web-application-code-and-state-using-evolutionary-search/

Also published