Zhenpeng Lin

dblp:277/7909 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0003-3593-4615ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 3 first-author · 10 since 2021
YearPublicationVenuePosition
2026 SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive Perspective
Yinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu
NDSS3
2024 Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
Dang K. Le, Zhenpeng Lin, Kyle Zeng, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé, Xinyu Xing 0001
USENIX Security Symposium3
2024 CAMP: Compiler and Allocator-based Heap Memory Protection
Zhenpeng Lin, Zheng Yu 0003, Simone Campanoni, Peter A. Dinda, Xinyu Xing 0001
USENIX Security Symposium1
2024 SeaK: Rethinking the Design of a Secure Allocator for OS Kernel
Zicheng Wang 0010, Yicheng Guang, Yueqi Chen 0001, Zhenpeng Lin, Michael V. Le, Dang K. Le, Dan Williams 0001, Xinyu Xing 0001, Zhongshu Gu, Hani Jamjoom
USENIX Security Symposium4
2024 Towards Unveiling Exploitation Potential With Multiple Error Behaviors for Kernel Bugs
abstract
Nowadays, fuzz testing has significantly expedited the vulnerability discovery of Linux kernel. Security analysts use the manifested error behaviors to infer the exploitability of one bug and thus prioritize the patch development. However, only using an error behavior in the report, security analysts might underestimate the exploitability of the kernel bug because it could manifest various error behaviors indicating different exploitation potentials. In this work, we conduct an empirical study on multiple error behaviors of kernel bugs to understand 1) the prevalence of multiple error behaviors and the possible impact of multiple error behaviors towards the exploitation potential; 2) the factors that manifest multiple error behaviors with different exploitation potential. We collectedall the fixed kernel bugsreported on Syzbot from September 2017 to January 2022, including 3,352 bug reports. We observed that multiple error behaviors manifested by kernel bugs are prevalent in the real world, and more error behaviors help unveil the exploitability of kernel bugs. Then we organized Linux kernel experts to analyze a sample of kernel bug dataset (484 bug reports, unique 162 bugs) and identified 6 key contributing factors to the mutiple error behaviors. Finally, based on the empirical findings, we propose an object-driven fuzzing technique to explore all possible error behaviors that a kernel bug might bring about. To evaluate the utility of our proposed technique, we implement our fuzzing toolGREBEand apply it to 60 real-world Linux kernel bugs. On average,GREBEcould manifest 2+ additional error behaviors for each of the kernel bugs. For 26 kernel bugs,GREBEdiscovers higher exploitation potential. We report to kernel vendors some of the bugs – the exploitability of which was wrongly assessed and the corresponding patch has not yet been carefully applied – resulting in their rapid patch adoption.
Ziqin Liu, Zhenpeng Lin, Yueqi Chen 0001, Yuhang Wu 0003, Yalong Zou, Dongliang Mu, Xinyu Xing 0001
IEEE Trans. Dependable Secur. Comput.2
2023 RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel Protections
abstract
Leveraging a control flow hijacking primitive (CFHP) to gain root privileges is critical to attackers striving to exploit Linux kernel vulnerabilities. Such attack has become increasingly elusive as security researchers propose capable kernel security mitigations, leading to the development of complex (and, as a trade-off, brittle and unreliable) attack techniques to regain it. In this paper, we obviate the need for complexity by proposing RetSpill, a powerful yet elegant exploitation technique that employs user space data already present on the kernel stack for privilege escalation.
Kyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing 0001, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao
CCS2
2023 Mitigating Security Risks in Linux with KLAUS: A Method for Evaluating Patch Correctness
Yuhang Wu 0003, Zhenpeng Lin, Yueqi Chen 0001, Dang K. Le, Dongliang Mu, Xinyu Xing 0001
USENIX Security Symposium2
2022 DirtyCred: Escalating Privilege in Linux Kernel
abstract
The kernel vulnerability DirtyPipe was reported to be present in nearly all versions of Linux since 5.8. Using this vulnerability, a bad actor could fulfill privilege escalation without triggering existing kernel protection and exploit mitigation, making this vulnerability particularly disconcerting. However, the success of DirtyPipe exploitation heavily relies on this vulnerability's capability (i.e., injecting data into the arbitrary file through Linux's pipes). Such an ability is rarely seen for other kernel vulnerabilities, making the defense relatively easy. As long as Linux users eliminate the vulnerability, the system could be relatively secure.
Zhenpeng Lin, Yuhang Wu 0003, Xinyu Xing 0001
CCS1
2022 An In-depth Analysis of Duplicated Linux Kernel Bug Reports
Dongliang Mu, Yuhang Wu 0003, Yueqi Chen 0001, Zhenpeng Lin, Chensheng Yu, Xinyu Xing 0001, Gang Wang 0011
NDSS4
2022 GREBE: Unveiling Exploitation Potential for Linux Kernel Bugs
abstract
Nowadays, dynamic testing tools have significantly expedited the discovery of bugs in the Linux kernel. When unveiling kernel bugs, they automatically generate reports, specifying the errors the Linux encounters. The error in the report implies the possible exploitability of the corresponding kernel bug. As a result, many security analysts use the manifested error to infer a bug’s exploitability and thus prioritize their exploit development effort. However, using the error in the report, security researchers might underestimate a bug’s exploitability. The error exhibited in the report may depend upon how the bug is triggered. Through different paths or under different contexts, a bug may manifest various error behaviors implying very different exploitation potentials. This work proposes a new kernel fuzzing technique to explore all the possible error behaviors that a kernel bug might bring about. Unlike conventional kernel fuzzing techniques concentrating on kernel code coverage, our fuzzing technique is more directed towards the buggy code fragment. It introduces an object-driven kernel fuzzing technique to explore various contexts and paths to trigger the reported bug, making the bug manifest various error behaviors. With the newly demonstrated errors, security researchers could better infer a bug’s possible exploitability. To evaluate our proposed technique’s effectiveness, efficiency, and impact, we implement our fuzzing technique as a tool GREBE and apply it to 60 real-world Linux kernel bugs. On average, GREBE could manifest 2+ additional error behaviors for each of the kernel bugs. For 26 kernel bugs, GREBE discovers higher exploitation potential. We report to kernel vendors some of the bugs – the exploitability of which was wrongly assessed and the corresponding patch has not yet been carefully applied – resulting in their rapid patch adoption.
Zhenpeng Lin, Yueqi Chen 0001, Yuhang Wu 0003, Dongliang Mu, Chensheng Yu, Xinyu Xing 0001
SP1
2020 A Systematic Study of Elastic Objects in Kernel Exploitation
abstract
Recent research has proposed various methods to perform kernel exploitation and bypass kernel protection. For example, security researchers have demonstrated an exploitation method that utilizes the characteristic of elastic kernel objects to bypass KASLR, disclose stack/heap cookies, and even perform arbitrary read in the kernel. While this exploitation method is considered a commonly adopted approach to disclosing critical kernel information, there is no evidence indicating a strong need for developing a new defense mechanism to limit this exploitation method. It is because the effectiveness of this exploitation method is demonstrated only on anecdotal kernel vulnerabilities. It is unclear whether such a method is useful for a majority of kernel vulnerabilities.
Yueqi Chen 0001, Zhenpeng Lin, Xinyu Xing 0001
CCS2