
kasld v0.4.0
KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration, and confinement — allows.
KASLD recovers the Linux kernel's virtual and physical memory layout — primarily the kernel text base — from a local process. What it can recover is a function of that process's vantage: its privileges and capabilities, the system's configuration, and any container confinement. It recovers the base outright where a leak or side channel allows, and otherwise narrows it to the smallest set of placements the available evidence supports.
The inference engine fuses evidence from dozens of independent techniques with the architecture's known invariants, narrowing the kernel's placement to a residual window — reported as the number of surviving slots (the placements KASLR could have chosen) and the bits of entropy they represent: an upper bound on the protection KASLR retains from this vantage, not a guarantee the base is beyond an attacker's reach (see docs/limitations.md).
Full recovery is often impossible on a hardened target — one where no direct kernel-text leak survives and the side channels its architecture and CPU expose are closed — but the constraint set is rarely empty. On architectures without KASLR, the engine locates the bootloader-chosen load address.
Supports:
- x86 (i386+, amd64)
- ARM (armv6, armv7, armv8, aarch64)
- MIPS (mipsbe, mipsel, mips64, mips64el)
- PowerPC (ppc, ppcle, ppc64, ppc64le)
- RISC-V (riscv32, riscv64)
- LoongArch (loongarch64)
- s390
Quick start
sudo apt install libc-dev make gcc binutils git
git clone https://github.com/bcoles/kasld
cd kasld
make
./build/<arch>/kasld
The build/<arch>/ directory is self-contained and can be deployed to a
target system:
build/<arch>/
kasld <- run this
components/ <- leak components
A hardened configuration (kernel.dmesg_restrict=1,
kernel.kptr_restrict=1, kernel.perf_event_paranoid=2 or higher,
kernel.unprivileged_bpf_disabled=1, and %pK pointer hashing) narrows the
filesystem-oracle
path, but is only one axis of the vantage:
side-channel, weak-entropy, and capability-granted techniques are
independent of these sysctls. For testing, the
extra/weaken-kernel-hardening script
can temporarily relax these settings (requires root).
Example output
The default text mode prints an answer-first overview:
KASLD 0.4.2-dev -- Kernel Address Space Layout Derandomization
Target: x86_64 / 7.0.0
Running 117 of 120 components (3 experimental skipped; use -x to enable)...
[####################] 100% 117/117 40.9s
1 component timed out after 30s and was killed (prefetch_directmap)
Quantity Certainty Window Candidates Grain
------------------- ---------- --------------------------------------- ---------------- -----
Virtual Image Base guaranteed 0xffffffff81000000 - 0xffffffffbd400000 483 of 512 2 MiB
Virtual Image Base likely 0xffffffff93400000 slide +0x12400000 1 2 MiB
Physical Image Base guaranteed 0x1000000 - 0x3d400000 474 2 MiB
Physical Image Base likely 0x1000000 - 0x3c29d000 474 2 MiB
Direct Map Base guaranteed 0xffff800000000000 - 0xffffa4aa80000000 37,547 1 GiB
Vmalloc Base guaranteed 0xffff898000000000 - 0xffffd6d580000000 79,191 of 79,191 1 GiB
Vmemmap Base guaranteed 0xffffa98040000000 - 0xfffffd0000000000 85,504 1 GiB
Module Region Base guaranteed 0xffffffffa0000000 - 0xffffffffff000000 389,121 4 KiB
Module Region Base likely 0xffffffffc0000000 - 0xffffffffc0400000 1,025 4 KiB
Paging Level guaranteed 48 1 of 2 -
Note: physical and virtual text randomize independently
Note: 1 sub-range excluded from the windows above; the counts
already reflect them (-v lists the ranges).
Evidence (1 finding, 2 components)
Region Position Address Sources
----------------- -------- ------------------ -------
virt kernel image base 0xffffffff93400000 2
[-v: detailed results, memory map, system info] [-H: hardening assessment]
The Certainty column separates two different claims about the same
quantity. A guaranteed row is proven: the true value lies inside that
window. A likely row is the single best estimate the evidence supports —
always a subset of the guaranteed window, and it may be wrong, because it
draws on signals below the soundness floor such as timing side channels. A
result worth acting on directly is a guaranteed row narrowed to one
candidate; a likely value is a lead to confirm, not a fact to rely on.
-v adds the full verbose readout (banner, system-config block,
per-component logs, KASLR analysis, memory-layout maps). -j emits
machine-readable JSON — the complete structured view, always including
the per-component records and the hardening assessment. -1 emits a
single shell-pipeable line. -m formats for issue trackers. -H
appends the hardening assessment to the text/markdown reports.
See docs/usage.md for the full CLI, output-mode details, explain mode, and hardening assessment.
Vantage
What KASLD can recover depends on the running process's vantage — not a single privilege level, but the combination of three independent things:
- Privileges, groups, and capabilities — an unprivileged uid, membership
in a group such as
adm(which grants the kernel logs under/var/log/), a container task holding an extra capability, or root. These do not form a single ladder, because filesystem permissions gate each source independently: a container grantedCAP_SYS_RAWIOis init-namespace root for that check and can read/proc/kcore— a leak an ordinary user cannot reach — while distributions differ over whether a file such as/boot/System.mapis world-readable at all. - System configuration —
kptr_restrict,dmesg_restrict,perf_event_paranoid, unprivileged BPF, kernel lockdown. Configuration is independent of privilege: root cannot read/proc/kallsymsunderkptr_restrict=2, while a relaxed sysctl or unprivileged BPF can hand a plain user a leak that a hardened system would deny. - Confinement — a namespace or seccomp sandbox that masks
/procoracles or blocks syscalls, narrowing what any privilege level observes.
The three axes gate each leak source independently — so more privilege is not a superset of less: configuration can deny a source to root, and side channels bypass the sysctls entirely. docs/usage.md has a leak-source-by-gate matrix showing which axis controls each source.