Skip to main navigation Skip to search Skip to main content

The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading Attacks

  • Xinhui Shao
  • , Zhen Ling*
  • , Yue Zhang
  • , Huaiyu Yan
  • , Yumeng Wei
  • , Lan Luo
  • , Zixia Liu
  • , Junzhou Luo
  • , Xinwen Fu
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Microcontroller-based IoT devices often use embedded real-time operating systems (RTOSs). Vulnerabilities in these embedded RTOSs can lead to compromises of those IoT devices. Despite the significance of security protections, the absence of standardized security guidelines results in various levels of security risk across RTOS implementations. Our initial analysis reveals that popular RTOSs such as FreeRTOS lack essential security protections. While Zephyr OS and ThreadX are designed and implemented with essential security protections, our closer examination uncovers significant differences in their implementations of system call parameter sanitization. We identify a performance optimization practice in ThreadX that introduces security vulnerabilities, allowing for the circumvention of parameter sanitization processes. Leveraging this insight, we introduce a novel attack named the Kernel Object Masquerading (KOM) Attack (as the attacker needs to manipulate one or multiple kernel objects through carefully selected system calls to launch the attack), demonstrating how attackers can exploit these vulnerabilities to access sensitive fields within kernel objects, potentially leading to unauthorized data manipulation, privilege escalation, or system compromise. We introduce an automated approach involving under-constrained symbolic execution to identify the KOM attacks and to understand the implications. Experimental results demonstrate the feasibility of KOM attacks on ThreadX-powered platforms. We reported our findings to the vendors, who recognized the vulnerabilities, with Amazon and Microsoft acknowledging our contribution on their websites.
Original languageEnglish
Title of host publicationProceedings of the 34th USENIX Security Symposium
PublisherUSENIX Association
Pages7507-7524
ISBN (Print)978-1-939133-52-6
Publication statusPublished - Aug 2025
Externally publishedYes
Event34th USENIX Security Symposium (USENIX Security '25) - Seattle, United States
Duration: 13 Aug 202515 Aug 2025
https://www.usenix.org/conference/usenixsecurity25

Conference

Conference34th USENIX Security Symposium (USENIX Security '25)
PlaceUnited States
CitySeattle
Period13/08/2515/08/25
Internet address

Fingerprint

Dive into the research topics of 'The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading Attacks'. Together they form a unique fingerprint.

Cite this