How I research
Linux kernel security
from security researchers
Sabyrzhan “novitoll” Tasbolatov
Spectre Security Group
Spectre Security Group
whom I research
Spectre Security Group
Spectre Security Group
some info might be incorrect due to
either lack of knowledge or misunderstanding the info from the source
Spectre Security Group
KASAN, KMSAN, KCSAN
Spectre Security Group
Dmitry Vyukov, 2018
Spectre Security Group
eBPF
Spectre Security Group
GCC plugins
Spectre Security Group
STACKLEAK in Linux mainline
Spectre Security Group
grsecurity / PaX teams
Spectre Security Group
Tough 2018
Spectre Security Group
Google Project Zero blog.
In-the-wild exploits for Linux, Android
Spectre Security Group
Spectre Security Group
Spectre Security Group
Spectre Security Group
Points to an array of function addresses that must be called, in-order, to perform initialization. Some of the entries in the array can be 0 or -1, and should be ignored.
Note: this is generally stored in a .init_array section
Thanks! Questions?
Spectre Security Group
Sabyrzhan “novitoll” Tasbolatov
Spectre Security Group