Skip to content

Glossary

KASLR (kernel ASLR)

Kernel Address Space Layout Randomization loads the kernel image at a random base each boot, so kernel function and gadget addresses are unknown to an attacker.

KASLR (Kernel Address Space Layout Randomization) is the kernel-space counterpart of ASLR: the kernel image is loaded at a randomized base address at each boot, so the locations of functions such as commit_creds and of ROP gadgets are not known ahead of time. A kernel exploit that needs those addresses must first obtain them.

Its defining weakness is that the kernel is a single contiguous image, so leaking any one kernel address — from a bug, an unrestricted /proc/kallsyms, dmesg, or a side channel — reveals the base and, with it, every symbol. Defenders pair KASLR with leak restrictions (kptr_restrict, dmesg_restrict) and, in hardened builds, FG-KASLR. See KASLR, KPTI and modern kernel defenses.