1 2 3<!DOCTYPE html> 4<html class="writer-html5" lang="en" data-content_root="../"> 5<head> 6 <meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" /> 7 8 <meta name="viewport" content="width=device-width, initial-scale=1.0" /> 9 <title>Introduction — kernelXDK 0.0.1 documentation</title> 10 <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=80d5e7a1" /> 11 <link rel="stylesheet" type="text/css" href="../_static/css/theme.css?v=e59714d7" /> 12 <link rel="stylesheet" type="text/css" href="../_static/collapsible-lists/css/tree_view.css?v=a885cde7" /> 13 14 15
15<script src="../_static/jquery.js?v=5d32c60e"></script>
15 16
16<script src="../_static/_sphinx_javascript_frameworks_compat.js?v=2cd50e6c"></script>
16 17
17<script src="../_static/documentation_options.js?v=d45e8c67"></script>
17 18
18<script src="../_static/doctools.js?v=9bcbadda"></script>
18 19
19<script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
19 20
20<script src="../_static/collapsible-lists/js/CollapsibleLists.compressed.js?v=73120307"></script>
20 21
21<script src="../_static/collapsible-lists/js/apply-collapsible-lists.js?v=660e4f45"></script>
21 22
22<script type="module" src="https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.esm.min.mjs"></script>
22 23
23<script type="module" src="https://cdn.jsdelivr.net/npm/@mermaid-js/[email protected]/dist/mermaid-layout-elk.esm.min.mjs"></script>
23 24
24<script type="module">import mermaid from "https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.esm.min.mjs";import elkLayouts from "https://cdn.jsdelivr.net/npm/@mermaid-js/[email protected]/dist/mermaid-layout-elk.esm.min.mjs";mermaid.registerLayoutLoaders(elkLayouts);mermaid.initialize({startOnLoad:false});</script>
24 25
25<script src="https://cdn.jsdelivr.net/npm/[email protected]/dist/d3.min.js"></script>
25 26
26<script type="module"> 27import mermaid from "https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.esm.min.mjs"; 28window.addEventListener("load", () => mermaid.run()); 29</script>
29 30
30<script src="../_static/js/theme.js"></script>
30 31 <link rel="index" title="Index" href="../genindex.html" /> 32 <link rel="search" title="Search" href="../search.html" /> 33 <link rel="next" title="KXDB Database" href="kxdb_database.html" /> 34 <link rel="prev" title="kernelXDK" href="../index.html" /> 35</head> 36 37<body class="wy-body-for-nav"> 38 <div class="wy-grid-for-nav"> 39 <nav data-toggle="wy-nav-shift" class="wy-nav-side"> 40 <div class="wy-side-scroll"> 41 <div class="wy-side-nav-search" > 42 43 44 45 <a href="../index.html" class="icon icon-home"> 46 kernelXDK 47 </a> 48<div role="search"> 49 <form id="rtd-search-form" class="wy-form" action="../search.html" method="get"> 50 <input type="text" name="q" placeholder="Search docs" aria-label="Search docs" /> 51 <input type="hidden" name="check_keywords" value="yes" /> 52 <input type="hidden" name="area" value="default" /> 53 </form> 54</div> 55 </div><div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="Navigation menu"> 56 <p class="caption" role="heading"><span class="caption-text">About</span></p> 57<ul class="current"> 58<li class="toctree-l1 current"><a class="current reference internal" href="#">Introduction</a><ul> 59<li class="toctree-l2"><a class="reference internal" href="#rationale-behind-the-kernelxdk">Rationale behind the kernelXDK</a></li> 60<li class="toctree-l2"><a class="reference internal" href="#limitations">Limitations</a></li> 61</ul> 62</li> 63<li class="toctree-l1"><a class="reference internal" href="#what-is-kernelxdk">What is kernelXDK?</a><ul> 64<li class="toctree-l2"><a class="reference internal" href="#tools">Tools</a></li> 65<li class="toctree-l2"><a class="reference internal" href="#future-ambitions">Future ambitions</a><ul> 66<li class="toctree-l3"><a class="reference internal" href="#mid-term-plans">Mid-term plans</a></li> 67<li class="toctree-l3"><a class="reference internal" href="#areas-to-explore">Areas to explore</a></li> 68</ul> 69</li> 70</ul> 71</li> 72<li class="toctree-l1"><a class="reference internal" href="kxdb_database.html">KXDB Database</a></li> 73</ul> 74<p class="caption" role="heading"><span class="caption-text">libxdk</span></p> 75<ul> 76<li class="toctree-l1"><a class="reference internal" href="../libxdk/README.html">What is libxdk?</a></li> 77<li class="toctree-l1"><a class="reference internal" href="../libxdk/README.html#installation">Installation</a></li> 78<li class="toctree-l1"><a class="reference internal" href="../libxdk/how_to_get_started.html">How to get started</a></li> 79<li class="toctree-l1"><a class="reference internal" href="../libxdk/sample_exploit.html">How to port an existing exploit</a></li> 80<li class="toctree-l1"><a class="reference internal" href="../libxdk/api.html">API Reference</a></li> 81</ul> 82<p class="caption" role="heading"><span class="caption-text">Command Line Tools</span></p> 83<ul> 84<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/image_db.html">Kernel Image DB</a></li> 85<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/image_runner.html">Kernel Image Runner</a></li> 86<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/kxdb_tool.html">KXDB Tool</a></li> 87<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/rop_generator.html">Kernel ROP Generator</a></li> 88</ul> 89 90 </div> 91 </div> 92 </nav> 93 94 <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap"><nav class="wy-nav-top" aria-label="Mobile navigation menu" > 95 <i data-toggle="wy-nav-top" class="fa fa-bars"></i> 96 <a href="../index.html">kernelXDK</a> 97 </nav> 98 99 <div class="wy-nav-content"> 100 <div class="rst-content"> 101 <div role="navigation" aria-label="Page navigation"> 102 <ul class="wy-breadcrumbs"> 103 <li><a href="../index.html" class="icon icon-home" aria-label="Home"></a></li> 104 <li class="breadcrumb-item active">Introduction</li> 105 <li class="wy-breadcrumbs-aside"> 106 <a href="../_sources/about/introduction.md.txt" rel="nofollow"> View page source</a> 107 </li> 108 </ul> 109 <hr/> 110</div> 111 <div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article"> 112 <div itemprop="articleBody"> 113 114 <section id="introduction"> 115<h1>Introduction<a class="headerlink" href="#introduction" title="Link to this heading">ï</a></h1> 116<section id="rationale-behind-the-kernelxdk"> 117<h2>Rationale behind the kernelXDK<a class="headerlink" href="#rationale-behind-the-kernelxdk" title="Link to this heading">ï</a></h2> 118<p>The rationale behind the current Beta version of the kernelXDK (Kernel eXploit Development Kit) is straightforward: we aim to create exploits that can be easily ported between kernelCTF versions.</p> 119<p>Currently, we are <a class="reference external" href="https://google.github.io/security-research/kernelctf/rules.html#3-exploits-for-cos-instances">
119compensating kernelCTF researchers extra</a> to port their exploits - for example, from LTS to COS. In the majority of cases, the only differences between these two exploits are the ROP chains or minimal spraying variations.</p> 120<p>kernelXDK aims to decouple target-specific information (symbol offsets, ROP chain gadgets, structure, and kmalloc cache information) from the exploit itself, thereby making the exploits target-independent. This approach allows us to easily introduce new targets for kernelCTF without the need to manually port existing exploits.</p> 121</section> 122<section id="limitations"> 123<h2>Limitations<a class="headerlink" href="#limitations" title="Link to this heading">ï</a></h2> 124<p>The current beta version of kernelXDK has several limitations and is currently only a proof-of-concept (v0.1, or Minimum Viable Product). It is focused on achieving a single, immediate goal (out of many future goals; see the âFuture ambitionsâ section): <strong>to ensure 50%â90% of kernelCTF exploits work across multiple kernelCTF targets</strong>.</p> 125</section> 126</section> 127<section id="what-is-kernelxdk"> 128<h1>What is kernelXDK?<a class="headerlink" href="#what-is-kernelxdk" title="Link to this heading">ï</a></h1> 129<p>kernelXDK is a set of tools designed to help kernel researchers write (currently Linux) kernel exploits more easily.</p> 130<section id="tools"> 131<h2>Tools<a class="headerlink" href="#tools" title="Link to this heading">ï</a></h2> 132<p>Descriptions of the specific tools are available in the README.md file within each respective folder and on the <a class="reference external" href="https://xdk.dev">xdk.dev</a> website.</p> 133<p>This graph shows how the tools interact with each other:</p> 134<pre class="mermaid"> 135 graph TD; 136 image_runner[**image_runner**: runs kernel images optionally with custom kernel modules] --> |can use vmlinuz images from the image db|image_db[**image_db:** downloads distro images and collects information about them] 137 image_db --> |uses runner to extract runtime information|image_runner 138 rop_generator[**rop_generator**: extracts ROP gadget and stack pivot information from kernel images] --> |can use the vmlinux files from the DB|image_db 139 image_db --> |uses ROP generator to extract ROP gadget and stack pivots information for images in the DB|rop_generator 140 kxdb_tool[**kxdb_tool**: generates .kxdb or .json database with all the target-specific information] --> |processes data from the image DB|image_db 141 libxdk[**libxdk**: C++ library provides target-specific information and exploitation primitives] --> |can use target information from .kxdb files generated by kxdb_tool|kxdb_tool 142 image_runner --> |compiles the kernel module|xdk_device[**xdk_device**: adds fake vulnerabilities, tracing and debugging capabilities for testing] 143 GHA[**Github Actions**] --> |tests the libxdk with image-runner using the xdk_device| libxdk 144 GHA --> |automatically builds database for new kernelCTF targets| kxdb_tool 145 exploit[**kernel exploit**] --> |links to the library|libxdk 146 exploit --> |uses or includes .kxdb files|kxdb_tool 147 exploit --> |optionally, uses the kernel module to introduce fake vulnerabilities|xdk_device 148 </pre></section> 149<section id="future-ambitions"> 150<h2>Future ambitions<a class="headerlink" href="#future-ambitions" title="Link to this heading">ï</a></h2> 151<section id="mid-term-plans"> 152<h3>Mid-term plans<a class="headerlink" href="#mid-term-plans" title="Link to this heading">ï</a></h3> 153<p>The following features are <strong>currently planned</strong> for the kernelXDK mid-term release. Please note that prioritization and inclusion will depend on the received Beta feedback.</p> 154<ul class="simple"> 155<li><p>More post-RIP approaches</p> 156<ul> 157<li><p><code class="docutils literal notranslate"><span class="pre">core_pattern</span></code> overwrite support</p></li> 158<li><p>[TBD] eBPF spraying support</p></li> 159</ul> 160</li> 161<li><p>KASLR leaks: EntryBleed / prefetch</p></li> 162<li><p>Smaller utility features</p> 163<ul> 164<li><p>namespace setup</p></li> 165<li><p>CPU pinning</p></li> 166<li><p>communication and synchronization primitives between threads</p></li> 167</ul> 168</li> 169<li><p>Spraying support</p> 170<ul> 171<li><p>Most common spraying primitives (<code class="docutils literal notranslate"><span class="pre">msg_msg</span></code>, <code class="docutils literal notranslate"><span class="pre">msg_msgseg</span></code>, <code class="docutils literal notranslate"><span class="pre">skbuff</span></code>, <code class="docutils literal notranslate"><span class="pre">user_key_payload</span></code>, <code class="docutils literal notranslate"><span class="pre">simple_xattrs</span></code>)</p></li> 172<li><p>Automatic limit bypasses (e.g. via forking)</p></li> 173<li><p>Leaking support (if primitive supports it)</p></li> 174<li><p>Victim object identification (determine which specific sprayed object was corrupted)</p></li> 175<li><p>Cross-cache support</p></li> 176<li><p>Dirty Pagetable support</p></li> 177</ul> 178</li> 179</ul> 180</section> 181<section id="areas-to-explore"> 182<h3>Areas to explore<a class="headerlink" href="#areas-to-explore" title="Link to this heading">ï</a></h3> 183<p>These represent longer-term ideas we plan to explore if the kernelXDK proves successful:</p> 184<ul class="simple"> 185<li><p><strong>Structured exploits (exploit recipes):</strong> add option to create exploits in a declarative manner instead of an imperative one, focus on the âwhatâ instead of the âhowâ.</p></li> 186<li><p><strong>Automatic exploit generation:</strong> enable kernelXDK to chain the right exploit primitives together to reach LPE from a vulnerability trigger.</p></li> 187<li><p><strong>Syzkaller-integration:</strong> generate exploits automatically from crashes.</p></li> 188<li><p><strong>Windows, macOS support.</strong></p></li> 189</ul> 190</section> 191</section> 192</section> 193 194 195 </div> 196 </div> 197 <footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer"> 198 <a href="../index.html" class="btn btn-neutral float-left" title="kernelXDK" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a> 199 <a href="kxdb_database.html" class="btn btn-neutral float-right" title="KXDB Database" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a> 200 </div> 201 202 <hr/> 203 204 <div role="contentinfo"> 205 <p>© Copyright 2025, Google.</p> 206 </div> 207 208 Built with <a href="https://www.sphinx-doc.org/">Sphinx</a> using a 209 <a href="https://github.com/readthedocs/sphinx_rtd_theme">theme</a> 210 provided by <a href="https://readthedocs.org">Read the Docs</a>. 211 212 213</footer> 214 </div> 215 </div> 216 </section> 217 </div> 218
218<script> 219 jQuery(function () { 220 SphinxRtdTheme.Navigation.enable(true); 221 }); 222 </script>
222 223 224</body> 225</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.