Don't Panic! Finding Bugs Hidden Behind Rust Runtime Safety Checks
Zeyang Zhuang, Zilun Wang, Wei Meng, Michael R. Lyu
Abstract
Rust has been extensively used in software and system development due to its guarantees for memory and concurrency safety. Fuzzing is a popular bug detection technique for examining the correctness and robustness of programs. However, we identify that current state-of-the-art Rust fuzzers are significantly impeded by the ubiquitous presence of Rust runtime safety checks, resulting in poor effectiveness and efficiency. These checks, which are inserted either implicitly by the compiler or explicitly by the compiler or developers, could cause a high number of panic crashes and early program termination in fuzzing. Consequently, current fuzzers are unable to effectively explore deep code behind the runtime safety checks, leaving potential vulnerabilities undetected. To address these limitations, we propose PanicKiller, a new Rust fuzzing technique to detect bugs hidden in deep and unsafe code. It performs a cross-IR analysis to precisely identify runtime safety checks and unsafe code in Rust programs, and employs a novel dynamic taint analysis to track the critical input bytes associated with the conditions enforced by these checks. PanicKiller further performs novel input prioritization and mutation strategies to achieve effective and efficient fuzzing. Our evaluation shows that PanicKiller significantly outperformed current state-of-the-art Rust fuzzers by achieving average improvements of 22.0× in bug exposure speed, 1.68× in code coverage, and 18.2× in false-positive crash reduction, and up to 129.0×, 2.10×, and 64.8× improvements, respectively. PanicKiller further helped detect 14 and 53 previously unknown vulnerabilities in the benchmark dataset and in the real world, with 11 RustSec IDs assigned. CCS Concepts • Security and privacy → Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1df62ab5-1660-4754-bce5-1b6df5eea26eCited by top-tier papers1
Ask how each one uses itBuilds on15
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar et al.NDSS 2017 · 700 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
Related papers
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 5 citations
- RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of RustKyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim et al.USENIX Security 2024 · 7 citations
- FRIES: Fuzzing Rust Library Interactions via Efficient Ecosystem-Guided Target GenerationXizhe Yin, Yang Feng, Qingkai Shi, Zixi Liu et al.ISSTA 2024 · 6 citations
- RPG: Rust Library Fuzzing with Pool-based Fuzz Target Generation and Generic SupportZhiwu Xu, Bohao Wu, Cheng Wen, Bin Zhang et al.ICSE 2024 · 9 citations
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 44 citations
