Lune

USENIX Security2024Top-tier venue

OptFuzz: Optimization Path Guided Fuzzing for JavaScript JIT Compilers

Jiming Wang, Yan Kang, Chenggang Wu, Yuhao Hu, Yue Sun, Jikai Ren, Yuanming Lai, Mengyao Xie, Charles Zhang, Tao Li, Zhe Wang

2024Year
7Citations
5Top-tier citations

Abstract

Just-In-Time (JIT) compiler is a core component of JavaScript engines, which takes a snippet of JavaScript code as input and applies a series of optimization passes on it and then transforms it to machine code. The optimization passes often have some assumptions (e.g., variable types) on the target JavaScript code, and therefore will yield vulnerabilities if the assumptions do not hold. To discover such bugs, it is essential to thoroughly test different optimization passes, but previous work fails to do so and mainly focused on exploring code coverage. In this paper, we present the first optimization path guided fuzzing solution for JavaScript JIT compilers, namely OptFuzz, which focuses on exploring optimization path coverage. Specifically, we utilize an optimization trunk path metric to approximate the optimization path coverage, and use it as a feedback to guide seed preservation and seed scheduling of the fuzzing process. We have implemented a prototype of OptFuzz and evaluated it on 4 mainstream JavaScript engines. On earlier versions of JavaScript engines, OptFuzz found several times more bugs than baseline solutions. On the latest JavaScript engines, OptFuzz discovered 36 unknown bugs, while baseline solutions found none. Table 1: Vulnerabilities in different optimizations. Category Vulnerability Description Instruction CVE-2019-5857 Error in comparison of -0 and null. CVE-2021-30598 Invalid right shift operation optimization. CVE-2021-30599 Wrong optimization of bitfield checks. CVE-2019-1366 Error in handle opcode Decr_A and Sub_A. Loop CVE-2019-8518 wrong hoisting GetByVal leading to OOB. CVE-2019-8623 LICM leaves stack variable uninitialized. CVE-2019-8671 LICM leaves object property access unguarded. CVE-2020-0828 Type confusion when hoisting variable fails. Function CVE-2018-4233 Type confusion caused by abstract interpreter. CVE-2020-9802 Integer range optimization error caused by CSE. Bug240720 The result of integer range analysis is incorrect. CVE-2019-9810 Incorrect alias information leading to OOB. CVE-2019-17026 Incorrect alias information leading to OOB. CVE-2019-26950 UAF caused by wrong side-effect analysis. CVE-2021-21230 Incorrect range information.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 4ffb9fae-817c-4ea9-9e9d-c47d67e2c801

Cited by top-tier papers5

Ask how each one uses it

Builds on18

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines