USENIX Security2026Top-tier venue
CombiSan: Unifying Software Sanitizers for Comprehensive Fuzzing
Matteo Marini, Floris Gorter, Daniele Cono D'Elia, Cristiano Giuffrida
Abstract
Modern C/C++ bug detection efforts heavily rely on fuzzing with software sanitizers. However, the most popular sanitizers have limited interoperability. As a result, developers often enable each sanitizer in isolation, if at all, requiring multiple runs. This sequential execution undermines performance and tests code in a non-uniform manner. In this paper, we present CombiSan, a fuzzing-optimized sanitizer that simultaneously detects all the addressability, uninitialized memory, and other undefined behavior issues covered by the three most popular sanitizers: ASan, MSan, and UBSan. CombiSan features a unified shadow memory design that efficiently tracks both the addressability and the initialization state of every byte of program memory. In addition, CombiSan's instrumentation seamlessly integrates with state-of-the-art detection of other undefined behavior classes. As bugs found by different sanitizers may mask each other by terminating execution early, CombiSan defers its analysis of all aggregated issues to test case completion. In our evaluation, CombiSan detected 81 new bugs in 10 programs tested daily by OSS-Fuzz. On average, fuzzing with CombiSan is 1.7x faster than sequentially testing with ASan+UBSan and MSan. Moreover, our results demonstrate that CombiSan has the same bug detection accuracy as these sanitizers, despite running for significantly fewer CPU hours.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b1353d1-3214-46ea-8c9d-df51fcedf048Builds on27
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 121 citations
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer et al.CCS 2016 · 97 citations
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 77 citations
Related papers
- QMSan: Efficiently Detecting Uninitialized Memory Errors During FuzzingMatteo Marini, Daniele Cono D'Elia, Mathias Payer, Leonardo QuerzoniNDSS 2025
- Debloating Address SanitizerYuchen Zhang, Chengbin Pang, Georgios Portokalidis, Nikos Triandopoulos et al.USENIX Security 2022
- FuZZan: Efficient Sanitizer Metadata Design for FuzzingYuseok Jeon, Wookhyun Han, Nathan Burow, Mathias PayerUSENIX ATC 2020 · 52 citations
- Practical Object-Level Sanitizer with Aggregated Memory Access and Custom AllocatorXiaolei Wang, Ruilin Li, Bin Zhang, Chao Feng et al.ICSE 2025
- WBSan: WebAssembly Bug Detection for Sanitization and Binary-Only FuzzingXiao Wu, Junzhou He, Liyan Huang, Cai Fu et al.WWW 2025 · 5 citations
