eBPF: Verifier Vulnerabilities and Exploitation.
Six Linux eBPF verifier vulnerabilities investigated in reproducible environments. Four complete local privilege-escalation chains, with their requirements and limits documented.
Problem & context
The eBPF verifier is a critical boundary between a submitted program and kernel execution. This academic investigation examined how known verifier vulnerabilities could produce practical exploitation primitives in deliberately vulnerable local environments.
Approach
Reproducible environments
Buildroot and QEMU/KVM provided vulnerable Linux environments, supported by kernel configurations and automation scripts.
From reachability to a primitive
The investigation considered vulnerability reachability, corruption primitives, capability requirements, and kernel mitigations.
Document successful and blocked paths
PoCs, exploitation chains, and a technical report document both complete chains and verifier checks encountered during the other investigations.
Supported outcomes
- Six verifier vulnerabilities investigated; four complete local privilege-escalation chains in the tested environments.
- Two capability-free uid=1000-to-root chains and two capability-to-root chains with explicitly controlled capability sets.
- One kernel-resident chain validated with SMEP and SMAP enabled; one ROP chain used kernel-space addresses. These are properties within the four-chain total.
- For two further vulnerabilities, documented verifier checks blocked the intended practical primitives in the tested investigation. These findings do not rule out other approaches.
Artifacts & scope
- Per-vulnerability investigations
- PoCs and exploits
- Kernel configurations and automation
- Reproducible environments and technical report
Academic project results apply to the tested vulnerable kernels and environments. They do not establish production exploitability or effectiveness against other kernels. Preliminary repository investigations remain subject to revalidation.