๐Ÿ›ก๏ธ CONFIG_STRICT_KERNEL_RWX & W^X Memory Invariants

CPU Hardware (Ring 0) x86: CR0.WP (Bit 16) WP = 1 (Write Protect) ARM64: SCTLR_EL1.WXN Memory Management Unit PTE Permission Check: _PAGE_RW == 0 (RO) _PAGE_NX == 1 (No-Exec) โš ๏ธ Malicious Vector Payload: Kernel Code Patch Target: Syscall Hooking Attempting Write... Kernel Virtual Memory Map .text (Kernel Code / Built-in Functions) Address: 0xffffffff81000000 | Size: ~12 MB R - X Invariants: Read-Only (Non-writable), Executable .rodata & __ro_after_init (Read-Only Data) Address: 0xffffffff82000000 | sys_call_table, static ops R - - Invariants: Read-Only (Non-writable), Non-Executable (NX=1) .data & .bss (Mutable Variables & State) Address: 0xffffffff82800000 | Active variables, locks R W - Invariants: Writable, Strictly Non-Executable (NX=1) Kernel Stack & Slab Heap (kmalloc / vmalloc) Dynamic memory buffers allocated during runtime R W - Invariants: Non-Executable (Shellcode execution blocked) W^X Invariant: โˆ€ Page P โˆˆ Kernel_VA, (Writable(P) โˆง Executable(P)) = False
1. W^X ๋ฉ”๋ชจ๋ฆฌ ๊ถŒํ•œ ๋ชจ๋ธ (ํ‘œ์ค€)
CONFIG_STRICT_KERNEL_RWX: ACTIVE
๋ฆฌ๋ˆ…์Šค ์ปค๋„์€ mark_readonly() ์ดˆ๊ธฐํ™” ๋ฃจํ‹ด์„ ํ†ตํ•ด ๋ชจ๋“  ๋ฉ”๋ชจ๋ฆฌ ํŽ˜์ด์ง€๋ฅผ Write XOR Execute ($W \oplus X$) ์›์น™์— ๋”ฐ๋ผ ๋ถ„๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

โ€ข .text (์ฝ”๋“œ): $R-X$ (์ฝ๊ธฐ/์‹คํ–‰ ๊ฐ€๋Šฅ, ์ˆ˜์ • ๋ถˆ๊ฐ€)
โ€ข .rodata (์ƒ์ˆ˜): $R--$ (์ฝ๊ธฐ ์ „์šฉ, ์‹คํ–‰ ๋ถˆ๊ฐ€)
โ€ข .data/์Šคํƒ/ํž™: $RW-$ (์ฝ๊ธฐ/์“ฐ๊ธฐ ๊ฐ€๋Šฅ, ์‹คํ–‰ ๋ถˆ๊ฐ€)
ํ•˜๋“œ์›จ์–ด ํ†ต์ œ ๋ฉ”์ปค๋‹ˆ์ฆ˜:
โ€ข x86_64: CPU ๋ ˆ์ง€์Šคํ„ฐ CR0.WP = 1 ํ™œ์„ฑํ™”๋กœ ์ปค๋„ ๋ชจ๋“œ(Ring 0)์—์„œ๋„ RO ํŽ˜์ด์ง€ ์“ฐ๊ธฐ ๊ธˆ์ง€.
โ€ข ARM64: ํŽ˜์ด์ง€ ํ…Œ์ด๋ธ” AP ์†์„ฑ ๋ฐ PXN/UXN ๋น„ํŠธ๋กœ ๋น„์‹คํ–‰ ๋ฐ ์“ฐ๊ธฐ ํ†ต์ œ.