Back to updates
New releaseSep 12, 2026

kasld v0.4.0

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration, and confinement — allows.

Share

KASLD logo generated with Copilot (cropped)

Build Status CodeQL Platform: Linux Architectures C99 Release License: MIT

KASLD recovers the Linux kernel's virtual and physical memory layout — primarily the kernel text base — from a local process. What it can recover is a function of that process's vantage: its privileges and capabilities, the system's configuration, and any container confinement. It recovers the base outright where a leak or side channel allows, and otherwise narrows it to the smallest set of placements the available evidence supports.

The inference engine fuses evidence from dozens of independent techniques with the architecture's known invariants, narrowing the kernel's placement to a residual window — reported as the number of surviving slots (the placements KASLR could have chosen) and the bits of entropy they represent: an upper bound on the protection KASLR retains from this vantage, not a guarantee the base is beyond an attacker's reach (see docs/limitations.md).

Full recovery is often impossible on a hardened target — one where no direct kernel-text leak survives and the side channels its architecture and CPU expose are closed — but the constraint set is rarely empty. On architectures without KASLR, the engine locates the bootloader-chosen load address.

Supports:

  • x86 (i386+, amd64)
  • ARM (armv6, armv7, armv8, aarch64)
  • MIPS (mipsbe, mipsel, mips64, mips64el)
  • PowerPC (ppc, ppcle, ppc64, ppc64le)
  • RISC-V (riscv32, riscv64)
  • LoongArch (loongarch64)
  • s390

Quick start

sudo apt install libc-dev make gcc binutils git
git clone https://github.com/bcoles/kasld
cd kasld
make
./build/<arch>/kasld

The build/<arch>/ directory is self-contained and can be deployed to a target system:

build/<arch>/
  kasld              <- run this
  components/        <- leak components

A hardened configuration (kernel.dmesg_restrict=1, kernel.kptr_restrict=1, kernel.perf_event_paranoid=2 or higher, kernel.unprivileged_bpf_disabled=1, and %pK pointer hashing) narrows the filesystem-oracle path, but is only one axis of the vantage: side-channel, weak-entropy, and capability-granted techniques are independent of these sysctls. For testing, the extra/weaken-kernel-hardening script can temporarily relax these settings (requires root).

Example output

The default text mode prints an answer-first overview:

KASLD 0.4.2-dev  --  Kernel Address Space Layout Derandomization
Target: x86_64 / 7.0.0

Running 117 of 120 components (3 experimental skipped; use -x to enable)...
[####################] 100%  117/117  40.9s
1 component timed out after 30s and was killed (prefetch_directmap)

  Quantity             Certainty   Window                                   Candidates        Grain
  -------------------  ----------  ---------------------------------------  ----------------  -----
  Virtual Image Base   guaranteed  0xffffffff81000000 - 0xffffffffbd400000        483 of 512  2 MiB
  Virtual Image Base   likely      0xffffffff93400000 slide +0x12400000                    1  2 MiB
  Physical Image Base  guaranteed           0x1000000 -         0x3d400000               474  2 MiB
  Physical Image Base  likely               0x1000000 -         0x3c29d000               474  2 MiB
  Direct Map Base      guaranteed  0xffff800000000000 - 0xffffa4aa80000000            37,547  1 GiB
  Vmalloc Base         guaranteed  0xffff898000000000 - 0xffffd6d580000000  79,191 of 79,191  1 GiB
  Vmemmap Base         guaranteed  0xffffa98040000000 - 0xfffffd0000000000            85,504  1 GiB
  Module Region Base   guaranteed  0xffffffffa0000000 - 0xffffffffff000000           389,121  4 KiB
  Module Region Base   likely      0xffffffffc0000000 - 0xffffffffc0400000             1,025  4 KiB
  Paging Level         guaranteed  48                                                 1 of 2  -

  Note: physical and virtual text randomize independently

  Note: 1 sub-range excluded from the windows above; the counts
        already reflect them (-v lists the ranges).

Evidence  (1 finding, 2 components)
  Region             Position  Address             Sources
  -----------------  --------  ------------------  -------
  virt kernel image  base      0xffffffff93400000        2

[-v: detailed results, memory map, system info]  [-H: hardening assessment]

The Certainty column separates two different claims about the same quantity. A guaranteed row is proven: the true value lies inside that window. A likely row is the single best estimate the evidence supports — always a subset of the guaranteed window, and it may be wrong, because it draws on signals below the soundness floor such as timing side channels. A result worth acting on directly is a guaranteed row narrowed to one candidate; a likely value is a lead to confirm, not a fact to rely on.

-v adds the full verbose readout (banner, system-config block, per-component logs, KASLR analysis, memory-layout maps). -j emits machine-readable JSON — the complete structured view, always including the per-component records and the hardening assessment. -1 emits a single shell-pipeable line. -m formats for issue trackers. -H appends the hardening assessment to the text/markdown reports.

See docs/usage.md for the full CLI, output-mode details, explain mode, and hardening assessment.

Vantage

What KASLD can recover depends on the running process's vantage — not a single privilege level, but the combination of three independent things:

  • Privileges, groups, and capabilities — an unprivileged uid, membership in a group such as adm (which grants the kernel logs under /var/log/), a container task holding an extra capability, or root. These do not form a single ladder, because filesystem permissions gate each source independently: a container granted CAP_SYS_RAWIO is init-namespace root for that check and can read /proc/kcore — a leak an ordinary user cannot reach — while distributions differ over whether a file such as /boot/System.map is world-readable at all.
  • System configuration — kptr_restrict, dmesg_restrict, perf_event_paranoid, unprivileged BPF, kernel lockdown. Configuration is independent of privilege: root cannot read /proc/kallsyms under kptr_restrict=2, while a relaxed sysctl or unprivileged BPF can hand a plain user a leak that a hardened system would deny.
  • Confinement — a namespace or seccomp sandbox that masks /proc oracles or blocks syscalls, narrowing what any privilege level observes.

The three axes gate each leak source independently — so more privilege is not a superset of less: configuration can deny a source to root, and side channels bypass the sysctls entirely. docs/usage.md has a leak-source-by-gate matrix showing which axis controls each source.

Categories