Kernel Mode Configuration
To enable kernel-mode ROP analysis, use thekernel_mode=True parameter:
Kernel-Specific Configuration
kernel_mode=True- Enable kernel-specific analysisfast_mode=False- Don’t skip complex gadgets (kernel has many)only_check_near_rets=False- Search more thoroughly for gadgetsmax_block_size=12- Allow longer gadgets common in kernel code
Kernel ROP chains typically require a kernel image with symbols (
vmlinux with debug symbols or vmlinux_sym). Without symbols, you’ll need to manually identify function addresses.Real-World Example: Linux Kernel Privilege Escalation
This example from angrop’s test suite (examples/linux_escape_chain/solve.py) demonstrates a complete kernel privilege escalation exploit:
Performance Characteristics
From the example’s documentation:Understanding the Privilege Escalation Chain
Let’s break down each step of the kernel escape chain:1
Escalate to root privileges
commit_creds() function installs new credentials. By passing init_cred (the kernel’s init process credentials), we gain root privileges.What it does: Sets current process credentials to root (UID 0, GID 0, full capabilities)2
Find the init process
task_struct for PID 1 (init process). Returns a pointer in rax.Why: The init process has full access to all namespaces, which we need for escaping containers.3
Move task pointer to argument register
rax (return value) to rdi (first argument).Why: We need this pointer as an argument to the next function call.4
Set up namespace pointer
rsi to point to init’s namespace proxy while preserving the task pointer in rdi.Why: switch_task_namespaces() needs both the task and the new namespace.5
Switch to init's namespaces
switch_task_namespaces() using the preserved register values as arguments.Why: Escapes container namespace isolation by adopting init’s namespaces (network, mount, PID, etc.)6
Fork to stabilize
7
Keep exploit alive
Key Kernel ROP Techniques
1. Calling Kernel Functions
In kernel mode, you call kernel functions directly by name or address:2. Using Kernel Structures
Kernel exploits often manipulate kernel data structures:3. Preserving Registers Across Kernel Calls
Kernel function calls often need to pass return values or maintain state:Kernel calling conventions are the same as userspace on x86_64:
rdi, rsi, rdx, rcx, r8, r9, then stack. However, some kernel-internal functions may use non-standard conventions.Finding Kernel Symbol Addresses
Method 1: /proc/kallsyms (Live System)
Method 2: System.map
Method 3: Kernel Binary Symbols
Common Kernel Exploit Patterns
Pattern 1: Simple Privilege Escalation
Pattern 2: Namespace Escape
Pattern 3: Disable Security Features
Pattern 4: Return to Userspace
Kernel ROP Challenges
1. SMEP/SMAP
Supervisor Mode Execution Prevention and Supervisor Mode Access Prevention prevent the kernel from executing or accessing userspace memory. Solutions:- Use kernel-only ROP (no userspace gadgets)
- Disable SMEP/SMAP via CR4 register manipulation
- Use kernel gadgets exclusively
2. KASLR
Kernel Address Space Layout Randomization randomizes kernel base address. Solutions:- Leak kernel addresses first
- Use kernel pointer disclosures
- Exploit
/proc/kallsymsif available - Use relative offsets from leaked addresses
3. Stack Canaries
Kernel stack canaries protect against buffer overflows. Solutions:- Leak canary values
- Bypass via other primitives (use-after-free, etc.)
- Overwrite canary with correct value
4. Limited Gadgets
Kernel binaries may have fewer useful gadgets than userspace. Solutions:- Use
fast_mode=Falseto find more gadgets - Increase
max_block_sizefor longer gadget sequences - Use
only_check_near_rets=Falsefor thorough search
Performance Optimization
Gadget Finding
Kernel Module ROP
For faster development, analyze vulnerable kernel modules instead of the entire kernel:Best Practices
- Always cache gadgets - Kernel gadget finding is extremely slow
- Use symbols when possible - Much easier than raw addresses
- Test incrementally - Build and verify each stage of the exploit
- Understand kernel internals - Know what functions do before calling them
- Check kernel version compatibility - Offsets change between versions
- Handle cleanup - Fork or sleep to prevent crashes after ROP
- Plan for KASLR - Design exploits to work with leaked addresses
Debugging Kernel ROP Chains
Advanced: Custom Kernel Configurations
Increasing
max_block_size, stack_gsize, and enabling cond_br significantly increases gadget finding time but may discover more powerful gadgets.Resources
- Linux Kernel Source: https://github.com/torvalds/linux
- Kernel Exploitation: https://github.com/xairy/linux-kernel-exploitation
- /proc/kallsyms documentation: https://www.kernel.org/doc/Documentation/filesystems/proc.txt
Next Steps
- Syscalls - Understanding kernel syscall interface
- Function Calls - Techniques applicable to kernel functions
- Badbytes - Handling restricted characters in kernel exploits