Bug Classes/Use after free

From Linux Kernel Security Subsystem
Revision as of 05:12, 4 February 2017 by DavidWindsor (talk | contribs) (Mitigations)
Jump to: navigation, search


When a memory allocation gets freed but there are still accidentally users of that memory, it is possible that an attacker could control the new memory allocation that fills the freed area, and then manipulate the contents in a way that the system uses its stale pointer and expects a different structure than is currently present. If there are function pointers contained in the structure, this allows for trivial execution control.



  • clearing memory on free can stop attacks where there is no reallocation control (e.g. PAX_MEMORY_SANITIZE)
  • segregating memory used by the kernel and by userspace can stop attacks where this boundary is crossed (e.g. PAX_USERCOPY)
  • randomizing heap allocations can frustrate the reallocation efforts the attack needs to perform (e.g. OpenBSD malloc)
  • reference counter overflow protection (PAX_REFCOUNT, HARDENED_ATOMIC)