SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept Exploits
Wei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang, Xiaojing Liao, Pan Bian, Bin Liang
Abstract
Patches and related information about so ware vulnerabilities are o en made available to the public, aiming to facilitate timely xes. Unfortunately, the slow paces of system updates (30 days on average) o en present to the a ackers enough time to recover hidden bugs for a acking the unpatched systems. Making things worse is the potential to automatically generate exploits on input-validation aws through reverse-engineering patches, even though such vulnerabilities are relatively rare (e.g., 5% among all Linux kernel vulnerabilities in last few years). Less understood, however, are the implications of other bug-related information (e.g., bug descriptions in CVE), particularly whether utilization of such information can facilitate exploit generation, even on other vulnerability types that have never been automatically a acked. In this paper, we seek to use such information to generate proofof-concept (PoC) exploits for the vulnerability types never automatically a acked. Unlike an input validation aw that is o en patched by adding missing sanitization checks, xing other vulnerability types is more complicated, usually involving replacement of the whole chunk of code. Without understanding of the code changed, automatic exploit becomes less likely. To address this challenge, we present SemFuzz, a novel technique leveraging vulnerabilityrelated text (e.g., CVE reports and Linux git logs) to guide automatic generation of PoC exploits. Such an end-to-end approach is made possible by natural-language processing (NLP) based information extraction and a semantics-based fuzzing process guided by such information. Running over 112 Linux kernel aws reported in the past ve years, SemFuzz successfully triggered 18 of them, and further discovered one zero-day and one undisclosed vulnerabilities. ese aws include use-a er-free, memory corruption, information leak, etc., indicating that more complicated aws can also be automatically a acked. is nding calls into question the way vulnerability-related information is shared today.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 69f66ece-51f1-4206-93e2-1f1a023236eaCited by top-tier papers45
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing et al.USENIX Security 2019 · 149 citations
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao et al.S&P 2022 · 139 citations
- ProFuzzer: On-the-fly Input Type Probing for Better Zero-Day Vulnerability DiscoveryWei You, Xueqiang Wang, Shiqing Ma, Jianjun Huang et al.S&P 2019 · 130 citations
- Constraint-guided Directed Greybox FuzzingGwangmu Lee, Woochul Shim, Byoungyoung LeeUSENIX Security 2021 · 99 citations
Builds on2
Related papers
- pPatch: Automated Vulnerability UnpatchingTianyi Jing, Pengyu Ding, Meng Xu, Yinhao Hu et al.FSE 2026
- GREBE: Unveiling Exploitation Potential for Linux Kernel BugsZhenpeng Lin, Yueqi Chen, Yuhang Wu, Dongliang Mu et al.S&P 2022 · 47 citations
- PAGENT: Program Analysis Guided LLM Agent for Proof-of-Concept GenerationAchintya Desai, Md Shafiuzzaman, Wenbo Guo, Tevfik BultanISSTA 2026
- PoCE: Automated Proof-of-Concept Synthesis using Large Language Models for Robust ValidationTanusree Das Tithy, Lamia Hasan Rodoshi, Ayman Rafid Azahar, Amlan Abhidarshi et al.ISSTA 2026
- PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm PackagesDeniz Simsek, Aryaz Eghbali, Michael PradelFSE 2026 · 4 citations
