A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel Fuzzing
Sanan Hasanov, Stefan Nagy, Paul Gazzillo
Abstract
The Linux kernel is actively-developed and widely-used. It supports billions of devices of all classes, from high-performance computing to the Internet-of-Things, in part because of its sophisticated configuration system, which automatically tailors the source code according to thousands of user-provided configuration options. Fuzzing has been highly successful at finding kernel bugs, being among the top bug reporters. Since the kernel receives 100s of patches per day, fuzzers run continuously, stopping regularly to rebuild the kernel with the latest changes before restarting fuzzing. But kernel fuzzers currently use predefined configuration settings that, as we show, exclude the majority of new patches from the kernel binary, nullifying the benefits of continuous fuzzing. Unfortunately, state-of-the-art configuration testing techniques are generally ill-suited to the needs of continuous fuzzing, excluding necessary options or requiring too many configuration files to be tractable. We distill down the needs of continuous testing into six properties with the most impact, systematically analyze the space of configuration selection strategies, and provide actionable recommendations. Through our analysis, we discover that continuous fuzzers can improve configuration variety without sacrificing performance. We empirically evaluate our discovery by modifying the configuration selection strategy for syzkaller, the most popular Linux kernel fuzzer, which subsequently found more than twice as many new bugs (35 vs. 13) than with the original configuration file and 12x more (24 vs. 2) when considering only unique bugs-with one security vulnerability being assigned a CVE.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 40035ffc-7594-464d-9261-53ac2d9048f1Cited by top-tier papers3
- Inferring 1-Minimal Trigger Configurations for Assessing Linux Kernel CVE TriggerabilityTongjie Wei, Peng Zhang, Zhiwen Hu, Xupu Hu et al.ISSTA 2026
- SyzParam: Incorporating Runtime Parameters into Kernel Driver FuzzingYue Sun, Yan Kang, Chenggang Wu, Kangjie Lu et al.CCS 2025
- Towards Better Linux Kernel Fault Localization: Leveraging Contrastive Reasoning and Hierarchical Context AnalysisHaichi Wang, Ruiguo Yu, Yesong Pang, Yingquan Zhao et al.ICSE 2026
Builds on30
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 156 citations
Related papers
- Thunderkaller: Profiling and Improving the Performance of SyzkallerYang Lan, Di Jin, Zhun Wang, Wende Tan et al.ASE 2023 · 2 citations
- SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement LearningDaimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian et al.USENIX Security 2021 · 75 citations
- SYSYPHUZZ: the Pressure of More CoverageZezhong Ren, Han Zheng, Zhiyao Feng, Qinying Wang et al.NDSS 2026 · 1 citation
- Fuzzing File Systems via Two-Dimensional Input Space ExplorationWen Xu, Hyungon Moon, Sanidhya Kashyap, Po-Ning Tseng et al.S&P 2019 · 117 citations
- SyzGen++: Dependency Inference for Augmenting Kernel Driver FuzzingWeiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou et al.S&P 2024 · 12 citations
