Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data Leakage

Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, Kang G. Shin

33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24

Overview

The "Go Go Gadget Hammer" talk at USENIX Security '24 introduces a novel and concerning approach to exploiting Rowhammer vulnerabilities, moving beyond the traditional targets of page table entries (PTEs) and sudo binaries. Presented by Youssef Tobah and his collaborators, this research demonstrates how a single bit flip in memory can be leveraged to achieve arbitrary read or write access by targeting general code patterns, termed "Rowhammer Gadgets." This work significantly broadens the attack surface for Rowhammer, posing a substantial threat to system security.

Watch on YouTube

Visual summary for Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data Leakage by Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, Kang G. Shin
Visual summary for Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data Leakage by Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, Kang G. Shin

Key moments

  1. 0:00 Introducing Go Gadget Hammer: new Rowhammer vulnerability
  2. 0:20 Quick recap on Rowhammer vulnerability mechanism
  3. 2:00 Prior Rowhammer exploitation and limitations of defenses
  4. 3:10 Defining Rowhammer Gadgets: general code patterns
  5. 4:20 Conceptualizing arbitrary read/write with a single bit flip
  6. 5:50 Exploiting struct pointers for widespread control
  7. 7:00 Overview of practical end-to-end Rowhammer attack stages

Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data Leakage

Speakers: Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, Kang G. Shin

Conference: USENIX Security '24

YouTube: https://www.youtube.com/watch?v=LJAFHBMpaB8

Overview

The "Go Go Gadget Hammer" talk at USENIX Security '24 introduces a novel and concerning approach to exploiting Rowhammer vulnerabilities, moving beyond the traditional targets of page table entries (PTEs) and sudo binaries. Presented by Youssef Tobah and his collaborators, this research demonstrates how a single bit flip in memory can be leveraged to achieve arbitrary read or write access by targeting general code patterns, termed "Rowhammer Gadgets." This work significantly broadens the attack surface for Rowhammer, posing a substantial threat to system security.

The core innovation lies in identifying common programming constructs—specifically, nested pointer dereferences where the final dereferenced value is returned to the user—as exploitable gadgets. By strategically flipping a bit within such a pointer, attackers can redirect execution flow or data access to attacker-controlled memory, effectively gaining control over crucial system functions. The researchers not only conceptualize this attack vector but also provide an end-to-end demonstration, achieving a kernel memory leakage rate of 82.6 bits per second, underscoring the practicality and severity of this new class of Rowhammer exploitation.

This presentation serves as a critical wake-up call for the security community, highlighting the limitations of current Rowhammer mitigations that primarily focus on protecting specific, known sensitive data structures. The findings advocate for a paradigm shift towards more holistic and fundamental defenses that prevent bit flips at their root, rather than merely containing their impact on a select few targets. The existence of hundreds of such gadgets within the Linux kernel, as estimated by the research, suggests a pervasive vulnerability that demands immediate attention.

Background

▶ Watch: Introducing Go Gadget Hammer: new Rowhammer vulnerability (0:00)

Rowhammer is a well-established memory vulnerability that allows an attacker to flip bits in DRAM without directly writing to the targeted memory location. This phenomenon arises from the physical characteristics of modern DRAM modules, which store data in arrays of capacitors. Each capacitor holds a charge representing a single bit (1 or 0). When a memory row is accessed, its charge is pulled into a row buffer and then restored. Rapidly accessing (or "hammering") adjacent "aggressor" rows can cause electrical disturbance effects, leading to charge leakage in nearby "victim" rows. If this leakage causes the charge in a victim capacitor to drop below a critical threshold, the stored bit can flip from 1 to 0 or vice versa.

First discovered in 2014, Rowhammer quickly garnered significant attention due to its ability to bypass traditional memory protection mechanisms. Subsequent research demonstrated its practicality across various devices, including mobile platforms, through web browsers, and on different DRAM generations, including DDR4 and DDR5. The overwhelming goal of prior Rowhammer exploitation has been to achieve privilege escalation, typically by corrupting critical system data structures.

The two most common methods for exploiting Rowhammer in prior work involve:

  1. Flipping Page Table Entries (PTEs): By flipping bits in PTEs, an attacker can manipulate memory mappings, granting arbitrary read/write access to any address in victim memory, including kernel space.
  2. Flipping bits in sudo binaries: Corrupting parts of the sudo utility can alter its behavior, allowing an unprivileged user to execute commands with root privileges.

In response to these threats, mitigation strategies have been proposed at both hardware and software levels. Hardware defenses often involve implementing Target Row Refresh (TRR) or similar mechanisms that attempt to detect Rowhammer-like access patterns and proactively refresh vulnerable rows. However, as demonstrated by continuous research, these hardware mitigations have largely proven insufficient, with successful bit flips still achievable on the latest DDR generations. Software defenses, predominantly academic proposals, focus on protecting specific victim data structures, such as placing sensitive values in "flip-safe" memory regions or isolating PTEs to prevent their corruption. The "Go Go Gadget Hammer" research critically challenges the effectiveness of these specific-target defenses by demonstrating a generalized exploitation method, rendering such localized protections inadequate against a broader attack surface.

Key Findings

▶ Watch: Prior Rowhammer exploitation and limitations of defenses (2:00)

The "Go Go Gadget Hammer" research unveils several critical findings that redefine the landscape of Rowhammer exploitation:

  1. A New Class of Rowhammer Vulnerability: The central contribution is the identification and exploitation of "Rowhammer Gadgets"—general code patterns that, when combined with a single bit flip, grant an attacker arbitrary read or write access. This shifts the focus from specific, static data structures (like PTEs) to dynamic code execution flows.
  2. Definition of a Rowhammer Gadget: A code snippet qualifies as a Rowhammer Gadget if it meets two key conditions:
  • It involves a nested pointer dereference.
  • The value of the second dereference is returned back to the calling user.
  1. Widespread Presence in Real-World Code: Using a modified version of the smatch tool, the researchers estimated approximately 192 read gadgets and 28 write gadgets present in the latest Linux kernel at the time of writing. While smatch is known for potential false positives/negatives, this estimate indicates a significant and pervasive vulnerability surface.
  2. End-to-End Exploitation Demonstrated: The team successfully performed an end-to-end attack on a specific gadget found in the pipe.c file of the Linux kernel. This practical demonstration proves that these generalized code patterns are indeed exploitable.
  3. Arbitrary Data Leakage: The end-to-end attack achieved a leakage rate of 82.6 bits per second by dumping kernel memory, confirming the ability to extract sensitive data from arbitrary kernel addresses.
  4. Call for Holistic Defenses: The work strongly emphasizes the need for more comprehensive, "holistic" Rowhammer defenses. Instead of merely protecting individual, known sensitive targets (like PTEs or sudo), future mitigations must aim to solve the root problem by preventing bit flips from occurring in the first place, or by fundamentally changing how pointers and critical data are handled in memory.

Technical Deep Dive

▶ Watch: Defining Rowhammer Gadgets: general code patterns (3:10)

The technical core of "Go Go Gadget Hammer" revolves around identifying and exploiting specific code patterns within a victim's execution flow. The attack hinges on the ability to induce a single bit flip in a strategically chosen memory location, which then redirects a pointer within a vulnerable code segment.

The conceptual foundation begins with a simple, yet powerful, observation: if a piece of code performs a nested pointer dereference and subsequently returns the value of the final dereference, it presents an opportunity. Consider a simplified example:

In this scenario, if an attacker can induce a bit flip in ptrA such that it now points to an attacker-controlled memory region, they can then populate that region with an arbitrary value for ptrB. Consequently, the second dereference (*ptrB) will now access an address chosen by the attacker, and that value will be returned to the calling user, effectively granting arbitrary read access.

The researchers quickly elevate this "toy example" to a more realistic and dangerous scenario by focusing on struct pointer dereferences. In large, complex codebases like the Linux kernel, it is extremely common to pack multiple variables into a single struct and then pass a pointer to this struct to functions, rather than passing numerous individual arguments. This leads to a common pattern of nested struct pointers, where a struct might contain pointers to other structs.

The danger escalates with struct pointers due to the "unpacking" behavior. If a bit flip compromises a struct pointer, it's not just a single variable that's affected, but potentially many. By flipping a struct pointer to point to an attacker-controlled, artificial struct copy, the attacker can effectively populate all local variables that are "unpacked" from this struct with their own malicious values. This allows the attacker to steer the victim code's execution flow or data access in arbitrary ways, leading to arbitrary read or write primitives.

For arbitrary write access, a similar concept applies to "write gadgets." These gadgets involve a single pointer dereference where the value of that dereference is an address to which data will be written. If a bit in this pointer can be flipped, the attacker can redirect the write operation to any desired memory address.

The practical realization of this attack involved overcoming two main challenges:

  1. Conceptual: Determining what a bit flip should do to yield arbitrary read/write. This was addressed by identifying the nested pointer dereference pattern.
  2. Practical: Achieving a bit flip in the right place at the right time. This required a multi-stage Rowhammer attack pipeline.

To discover these gadgets in the Linux kernel, the researchers adapted smatch, a static analysis tool primarily used for debugging the Linux kernel. smatch had previously been extended to find Spectre gadgets, and the team modified it further to identify both read and write Rowhammer gadgets based on their defined criteria. The tool reported 192 read gadgets and 28 write gadgets. It's important to note that static analysis tools like smatch can have false positives and false negatives, meaning these numbers are estimates rather than definitive counts, but they strongly suggest a widespread vulnerability.

Demo / Proof of Concept

▶ Watch: Exploiting struct pointers for widespread control (5:50)

The "Go Go Gadget Hammer" research culminated in a successful end-to-end demonstration of the attack, proving the practicality of exploiting these general code patterns. The attack followed the typical four stages of a Rowhammer exploit:

  1. Memory Templating: This initial phase involves systematically hammering various memory addresses to identify which physical pages and specific offsets are susceptible to bit flips. The goal is to locate a physical page that reliably produces a bit flip at the precise offset required to corrupt a target pointer within a Rowhammer gadget.
  2. Memory Massaging: Once a flip-vulnerable physical page is identified, the next step is to manipulate the victim's memory allocator to ensure that the vulnerable gadget's critical pointer variable is allocated on this specific physical page. This guarantees that when the Rowhammer attack is triggered, the bit flip will occur in the intended variable.
  3. Populating Victim Memory (Heap Spray): The attack targets pointers that typically point to heap data. To achieve arbitrary control, the attacker must populate victim memory with their own artificial data structures. This is accomplished through a heap spray, where the attacker allocates numerous copies of their malicious struct in the heap. When the target pointer is flipped, it will be redirected to one of these attacker-controlled struct copies.
  4. Calling the Victim Function and Flipping the Pointer: Finally, the victim function containing the Rowhammer Gadget is called. While the function executes, the Rowhammer primitive is activated to induce a bit flip in the targeted pointer variable. This flipped pointer then points to one of the attacker's artificial struct copies created during the heap spray. From this point, the attacker can cycle through the data in their controlled addresses, effectively steering the dereferenced pointer to arbitrary memory locations and leaking their contents.

For their end-to-end proof of concept, the researchers selected a specific Rowhammer Gadget found in the pipe.c file within the Linux kernel. This particular code segment is normally responsible for determining the length of a pipe that has been inserted into the kernel. It exhibits the key characteristics of a Rowhammer Gadget: it unpacks multiple variables from a single struct pointer, and it includes a nested pointer dereference, in this case taking the form of an array access (struct_ptr->array[index]).

By executing all four attack stages against this pipe.c gadget, the researchers successfully demonstrated arbitrary kernel memory leakage. The attack achieved a significant leakage rate of 82.6 bits per second, allowing them to dump sensitive kernel memory contents. This concrete demonstration underscores that Rowhammer Gadgets are not merely theoretical constructs but represent a practical and exploitable vulnerability in real-world systems like the Linux kernel.

Defensive Implications

▶ Watch: Overview of practical end-to-end Rowhammer attack stages (7:00)

The "Go Go Gadget Hammer" research carries profound defensive implications, fundamentally challenging the efficacy of current Rowhammer mitigation strategies. Historically, defenses have largely focused on protecting specific, high-value targets such as page table entries (PTEs) or critical sudo binaries. These approaches often involve placing sensitive data in "flip-safe" memory regions or implementing highly localized protection mechanisms. However, by demonstrating that Rowhammer can be exploited through general code patterns (gadgets), this work exposes the inherent weakness of such target-specific defenses.

The primary defensive implication is the urgent need for more holistic Rowhammer defenses. Instead of playing a perpetual game of whack-a-mole by identifying and protecting individual sensitive data structures, the security community must pivot towards solutions that address the root cause of Rowhammer: the uncontrolled bit flips themselves. This means designing and implementing mitigations that either:

  1. Prevent bit flips entirely: This could involve advancements in DRAM technology to make capacitors more robust to disturbance effects, or more effective hardware-level refresh mechanisms (beyond current TRR implementations) that genuinely prevent bit flips under aggressive hammering conditions.
  2. Render bit flips harmless at a systemic level: This is a more challenging prospect but could involve architectural changes to how memory is accessed, how pointers are handled, or how critical data is structured and verified such that a single bit flip in a pointer or data value does not automatically lead to arbitrary code execution or data leakage. For instance, implementing stronger memory tagging, pointer authentication, or always-on error-correcting codes (ECC) that are robust enough to detect and correct Rowhammer-induced flips could be considered.

Furthermore, the discovery of numerous gadgets in the Linux kernel highlights the need for:

  • Improved static and dynamic analysis tools: Tools capable of accurately identifying these generalized code patterns in large codebases are crucial for understanding the full attack surface and prioritizing remediation efforts.
  • Secure coding practices: Developers should be educated on the risks associated with nested pointer dereferences and the potential for memory corruption, even if the direct cause is a physical memory bug. While not a direct solution to Rowhammer, robust input validation and defensive programming could minimize the impact of such flips.
  • Rethinking memory allocation: Memory massaging techniques are central to the attack. Defenses could explore ways to make it harder for attackers to reliably co-locate vulnerable gadgets with flip-susceptible physical memory pages.

In essence, the research underscores that as long as Rowhammer bit flips remain practically achievable, attackers will continue to find creative ways to leverage them. Therefore, the focus must shift from protecting specific outcomes to preventing the fundamental vulnerability itself, or at least significantly raising the bar for its exploitation across a broad spectrum of code patterns.

Key Takeaways

  • Generalized Rowhammer Exploitation: Rowhammer attacks can now target general code patterns (Rowhammer Gadgets) involving nested pointer dereferences, moving beyond specific targets like PTEs or sudo binaries.
  • Arbitrary Read/Write Primitives: A single bit flip in a strategically chosen pointer within a Rowhammer Gadget can grant attackers arbitrary read or write access to kernel memory.
  • Widespread Vulnerability: Hundreds of such Rowhammer Gadgets (over 200) were estimated to exist in the Linux kernel, indicating a pervasive and significant attack surface.
  • Practical End-to-End Attack: An end-to-end attack on a gadget in pipe.c successfully demonstrated kernel memory leakage at a rate of 82.6 bits per second, proving the practicality of this new exploitation vector.
  • Limitations of Current Mitigations: Existing Rowhammer defenses, which primarily focus on protecting specific sensitive data structures, are insufficient against this generalized attack methodology.
  • Need for Holistic Defenses: The research strongly advocates for a paradigm shift towards holistic Rowhammer defenses that prevent bit flips at their root or render them harmless at a systemic level, rather than just protecting individual victims.

About the Speaker(s)

The "Go Go Gadget Hammer" research was presented by Youssef Tobah and was a collaborative effort with Andrew Kwong, Ingab Kang, Daniel Genkin, and Kang G. Shin. While the transcript primarily features Youssef Tobah as the presenter, the collective expertise of the team from their respective institutions (not explicitly detailed in the provided transcript but typically associated with such academic research) was instrumental in uncovering and demonstrating this novel Rowhammer exploitation technique. Kang G. Shin is a prominent figure in computer science research, particularly in areas of embedded systems, real-time computing, and security.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research unveils a critical paradigm shift in Rowhammer exploitation by introducing "Rowhammer Gadgets" – general nested pointer dereference patterns in code. It demonstrates a novel method to achieve arbitrary kernel read/write, rendering current specific-target mitigations obsolete and demanding a systemic re-evaluation of Rowhammer defenses. This is a must-see for anyone serious about memory security.

Heather Calloway (CISO) — MUST SEE

This research fundamentally redefines Rowhammer exploitation, exposing a pervasive vulnerability in general code patterns that renders current, target-specific mitigations inadequate. It forces a critical re-evaluation of system-level memory safety and demands a holistic approach to foundational security. Every CISO and engineering leader needs to understand these implications for their institutional risk posture.

→ Top-rated talks at 33rd USENIX Security Symposium

All talks from 33rd USENIX Security Symposium