Industry practice of coverage-guided enterprise Linux kernel fuzzing
Abstract
Coverage-guided kernel fuzzing is a widely-used technique that has helped kernel developers and testers discover numerous vulnerabilities. However, due to the high complexity of application and hardware environment, there is little study on deploying fuzzing to the enterprise-level Linux kernel. In this paper, collaborating with the enterprise developers, we present the industry practice to deploy kernel fuzzing on four different enterprise Linux distributions that are responsible for internal business and external services of the company. We have addressed the following outstanding challenges when deploying a popular kernel fuzzer, syzkaller, to these enterprise Linux distributions: coverage support absence, kernel configuration inconsistency, bugs in shallow paths, and continuous fuzzing complexity. This leads to a vulnerability detection of 41 reproducible bugs which are previous unknown in these enterprise Linux kernel and 6 bugs with CVE IDs in U.S. National Vulnerability Database, including flaws that cause general protection fault, deadlock, and use-after-free.
BibTeX
@inproceedings{Shi-al:FSE19,
author = {Heyuan Shi and
Runzhe Wang and
Ying Fu and
Mingzhe Wang and
Xiaohai Shi and
Xun Jiao and
Houbing Song and
Yu Jiang and
Jiaguang Sun},
title = {Industry practice of coverage-guided enterprise Linux kernel fuzzing},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {986--995},
publisher = {{ACM}},
year = {2019},
}