AI 中文总结
该研究提出框架FCC,可推断满足Kconfig且经make olddefconfig验证的1-最小Linux内核CVE触发配置,提升配置成功率并减小候选集规模,助力供应商评估CVE触发可能性。
AI 中文摘要
评估Linux内核CVE的供应商需要知道漏洞在生产定制配置下是否可触发,而非仅知道某个版本是否受影响,但上游复现器和漏洞数据库很少提供配置级上下文。我们研究最小触发配置推断:给定一个CVE条目和目标内核版本(可选基线.config),我们合成一组满足Kconfig的选项,该选项在执行make olddefconfig后仍有效,且当存在复现器时,在指定评估协议下仍能触发;随后将其修剪为1-最小(子集最小)边界以用于评估。我们的框架FCC将漏洞线索与构建系统符号关联,在olddefconfig反馈下完成隐式前提条件以避免静默回退,并在依赖拓扑引导下执行运行时验证的最小化。我们在KernJC和KernelCTF上进行评估,共涉及多个内核版本的88个CVE。在这88个CVE的集合上,FCC将make olddefconfig后的配置成功率从仅使用olddef注入基线的62.5%(55/88)提升至96.6%(85/88);在KernJC集合上,与KernJC相比,FCC将平均候选集大小降低了78.7%(每个CVE平均14.72个选项 vs 69.00个选项)。对时间和token成本的分阶段分析显示,第一阶段占主导开销,而聚焦于CVE的证据选择可大幅降低该成本。通过返回有效且可审计的1-最小配置边界,FCC帮助供应商针对其部署配置界定触发可能性,提供一条清晰、工具支持的决策线。
英文摘要
Vendors assessing Linux kernel CVEs need to know whether a bug is triggerable under production-tailored configurations, not merely whether a version is affected, yet upstream reproducers and vulnerability databases rarely provide configuration-level context. We study minimal trigger-configuration inference: given a CVE entry and a target kernel version (optionally a baseline .config), we synthesize a Kconfig-satisfiable option set that remains effective after make olddefconfig and, when a reproducer is available, still triggers under a specified evaluation protocol; we then prune it to a 1-minimal (subset-minimal) boundary for evaluation. Our framework FCC links vulnerability cues to build-system symbols, completes implicit prerequisites under olddefconfig feedback to avoid silent rollback, and performs runtime-validated minimization guided by dependency topology. We evaluate on KernJC and KernelCTF, totaling 88 CVEs across multiple kernel versions. On the 88-CVE set, FCC improves the post-make olddefconfig configuration success rate from 62.5% (55/88) to 96.6% (85/88) over an olddef-only injection baseline; on the KernJC set, FCC reduces the average candidate set size by 78.7% compared to KernJC (Avg. 14.72 vs. 69.00 options per CVE). A stage-wise analysis of time and token costs shows that Stage I dominates overhead, while CVE-focused evidence selection substantially reduces this cost. By returning an effective and auditable 1-minimal configuration boundary, FCC helps vendors scope triggerability against their deployment configurations with a clear, tool-supported decision line.
Comments22 pages, 7 figures. Accepted to ISSTA 2026