KASLR, KPTI and Modern Kernel Defenses
Kernel address randomization, page-table isolation, and the config options that harden a Linux kernel against memory-corruption exploits — what each one stops and how to enable it.
Memory safety, from the defender's side
A structured reference to memory-corruption vulnerabilities in C and C++: how stack and heap overflows, use-after-free and integer bugs happen, and how compilers, sanitizers, fuzzers and safer languages stop them.
Memory map
Start with how memory is laid out, learn the classes of bugs that corrupt it, then the layers that prevent, detect, contain and triage them.
Stack, heap, ELF segments and calling conventions: the terrain every bug lives on.
Overflows, use-after-free, double free, integer and format-string bugs, and how to spot them.
Canaries, NX/DEP, ASLR/PIE, RELRO, FORTIFY_SOURCE, CFI, CET and PAC, and how to verify them.
AddressSanitizer, UBSan and coverage-guided fuzzing with libFuzzer and AFL++.
Read signals, backtraces, sanitizer reports and core dumps, and decide what to fix first.
Memory-safe languages, safer C++ and a realistic migration strategy.
A staged, legal path from C and assembly to CTF pwn challenges and security careers.
ret2win, ret2libc, ROP chains, GOT overwrites and format-string primitives, built and defeated in a lab.
AArch64 calling conventions, the link register, ROP on ARM, and the PAC and BTI defences.
Privilege escalation from a kernel bug: the credential model, ret2usr, and SMEP, SMAP, KASLR and KPTI.
SEH overwrites, DEP bypass with ROP, and the SafeSEH, SEHOP, ASLR, CFG and CET mitigations.
Defense in depth
Every mitigation has gaps. Real resilience comes from stacking layers so a bug that slips past one is caught or contained by the next.
Memory-safe languages, bounds-checked APIs, compiler warnings and code review stop bugs from being written.
ASan, UBSan and coverage-guided fuzzing surface the bugs that were written, before an attacker does.
Canaries, NX, ASLR/PIE, RELRO, CFI and shadow stacks make the remaining bugs hard to exploit.
Crash triage, core dumps and deduplication turn field crashes into prioritised fixes.
Latest guides
Kernel address randomization, page-table isolation, and the config options that harden a Linux kernel against memory-corruption exploits — what each one stops and how to enable it.
A kernel memory-corruption bug is about privilege, not a shell. The credential model, the commit_creds(prepare_kernel_cred(0)) payload, and returning cleanly to userspace — in a lab VM.
The kernel once trusted userspace memory, so exploits just pointed kernel execution at a user payload. SMEP and SMAP ended that — and how kernel ROP works around them.
Every exploit walks the same stages: bug, corruption, hijack, code execution, escalation. A defender's checklist of which mitigation stops each — across Linux, ARM, Windows and the kernel.
DEP makes stack shellcode unrunnable, so a Windows ROP chain calls VirtualProtect to mark the shellcode region executable, then jumps to it. Build it with mona, then see ASLR and CFG respond.
How SafeSEH, SEHOP, ASLR, Control Flow Guard and hardware CET each close a Windows exploitation technique — what they check, how to enable them, and their limits.
Glossary
Short, precise definitions of the terms you will meet in advisories, crash reports and compiler docs.
Editorial line
Understanding exploitation is what makes mitigations make sense. We teach the mechanics at the level a secure coder, reviewer or incident responder needs, and stop short of weaponisation.
What you will find
What we never publish