Hao-Yu Yang & Yu-Ting Lin

Harvest Season for SLUB: From io_uring vulnerability to Novel Sheaf-Based Exploitation Techniques

Abstract

This research investigates io_uring and the security problems and exploitation techniques associated with the new SLUB allocator sheaf/barn mechanism in the Linux kernel. As the Linux kernel continues to improve I/O performance and memory management efficiency, these new kernel mechanisms enhance system performance but also introduce a new attack surface.

Two 0-days in io_uring are first presented: a race condition between CQ/SQ ring resize and deferred task work, and a UAF caused by the error handling path of the provided-buffer bundle feature. Using these vulnerabilities, Linux local privilege escalation is achieved in an environment with multiple kernel protections enabled.

While building the exploit chain, the new SLUB sheaf/barn mechanism was found to change the traditional life-cycle behavior of objects, preventing common exploitation techniques such as cross-cache attack from working as expected. The sheaf/barn mechanism is therefore analyzed in depth, and several methods are proposed to address its impact on existing exploitation techniques. In addition, a flaw arising from the design gap between the traditional SLUB freelist mitigation and sheaf is revealed and put to use in the exploitation.

Finally, three novel exploitation techniques based on the sheaf mechanism are proposed. One of them removes the traditional cross-cache attack's dependence on the buddy system, allowing an attacker to steer objects between different cache pools more flexibly and stably, and this technique is further used to build another new exploit chain for the second vulnerability.

BIO

Hao-Yu Yang (naup96321, also known as 堇姬 Naup). I'm currently studying Computer Science at National Yang Ming Chiao Tung University. I'm a member of the CakeisTheFake and Squid Proxy Lovers CTF teams. As a pwner, I currently focus on Linux kernel security research.

Yu-Ting Lin is pursuing a Bachelor's degree in Computer Science at National Yang Ming Chiao Tung University. His research focuses on Natural Language Processing, AI Safety, AI Security, and Binary Exploitation. His work has appeared at both domestic and international venues, including Eval4NLP (IJCNLP-AACL 2023), ROCLING (ACLCLP), and CURE-Bench (NeurIPS 2025). He was also selected to represent Taiwan at the Global Cybersecurity Camp (GCC) 2026.