logo

Xen SMEP & SMAP Bypass Technique Analysis

ID: 11190848-9f02-5a85-abfe-f9ba3bed7638

STIX ID: report--11190848-9f02-5a85-abfe-f9ba3bed7638

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-07-31

...
...

This 2015 technical blog explains how Xen's direct-mapped memory and the guest-exposed physical-to-machine (p2m) mapping can be abused to bypass SMEP and SMAP by computing DIRECTMAP_VIRT_START + MFN to obtain a ring0-only RWX virtual address that points to guest-controlled data, enabling hypervisor-level code execution from a compromised guest; the author demonstrates the technique, provides example code, discusses payload staging and data tunnelling, and suggests mitigations such as making the direct map non-executable or randomising hypervisor memory layout.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.