arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.23889cs.CRcs.AI

SyzHarness:基于补丁的内核漏洞复现与LLM合成的模糊测试驱动

SyzHarness: Patch-Based Kernel Bug Reproduction with LLM-Synthesized Fuzzing Harnesses

Xingyu Li, Juefei Pu, Haonan Li, Arrdya Srivastav, Kareem Shehada, Srikanth V. Krishnamurthy, Zhiyun Qian

首次发表
浏览论文内容

中文总结 AI 辅助

SyzHarness结合LLM推理与覆盖率引导模糊测试,通过合成参数化驱动并迭代优化,在多个数据集上实现高成功率的内核漏洞复现。

中文摘要 AI 辅助

自动化内核漏洞复现对于漏洞分类、补丁验证和回归测试至关重要,但目前仍缺乏有效且高效的解决方案。核心挑战有两方面:复现器必须首先恢复到达易受攻击状态所需的触发脚手架,并确定实际触发漏洞的精确具体值。现有的定向模糊测试方法在恢复必要的触发脚手架方面效果不佳,而仅依赖LLM的生成方法则因难以发现具体值和应对运行时不确定性而脆弱。我们设计了SyzHarness,一个结合LLM推理与覆盖率引导模糊测试的框架,用于基于补丁的Linux内核漏洞复现。给定一个补丁,SyzHarness使用由代码导航工具支撑的LLM代理来合成一个参数化的模糊测试驱动,该驱动修复了前置设置逻辑,同时仅暴露不确定的、关键漏洞的输入参数供Syzkaller进行变异。然后,SyzHarness将该驱动转换为Syzkaller兼容的接口,并使用分层可达性反馈迭代优化它。我们在多个可触发的真实世界Linux内核漏洞数据集上评估了SyzHarness。在100个KernelCTF案例中,SyzHarness实现了78%的漏洞复现成功率。在SyzDirect基准测试中,SyzHarness实现了73%的漏洞复现成功率,显著优于先前的定向灰盒模糊测试。在2026年3月之后修复的50个近期已知可触发的syzbot漏洞中,SyzHarness仅使用修复提交作为输入就复现了40/50(80%)。

英文摘要

Automated kernel vulnerability reproduction is essential for bug triage, patch validation, and regression testing, but still lacks an effective and efficient solution. The core challenge is twofold: a reproducer must first recover the trigger scaffold needed to reach the vulnerable state and determine the precise concrete values that actually trigger the bug. Existing directed fuzzing approaches are ineffective at recovering the necessary trigger scaffold, while LLM-only generation is brittle because it struggles with concrete-value discovery and runtime nondeterminism. We design SyzHarness, a framework that combines LLM reasoning with coverage-guided fuzzing for patch-based Linux kernel vulnerability reproduction. Given a patch, SyzHarness uses an LLM agent grounded by code navigation tools to synthesize a parameterized fuzzing harness that fixes the prerequisite setup logic while exposing only uncertain, bug-critical input parameters to be mutated by Syzkaller. SyzHarness then translates this harness into a Syzkaller compatible interface and iteratively refines it using hierarchical reachability feedback. We evaluate SyzHarness on multiple datasets of triggerable real-world Linux kernel vulnerabilities. On 100 KernelCTF cases, SyzHarness achieves a 78% bug reproduction success rate. On the SyzDirect benchmark, SyzHarness achieves a 73% bug reproduction success rate, substantially outperforming prior directed greybox fuzzing. On 50 recent, known-triggerable syzbot bugs fixed after March 2026, SyzHarness reproduces 40/50 (80%) using only the fix commits as input.

发表机构

  • University of California, Riverside(加州大学河滨分校)

机构由 AI 辅助整理,请以论文原文为准。

↑