KIT: Testing OS-Level Virtualization for Functional Interference Bugs
Congyu Liu, Sishuai Gong, Pedro Fonseca
Abstract
Container isolation is implemented through OS-level virtualization, such as Linux namespaces. Unfortunately, these mechanisms are extremely challenging to implement correctly and, in practice, suffer from functional interference bugs, which compromise container security. In particular, functional interference bugs allow an attacker to extract information from another container running on the same machine or impact its integrity by modifying kernel resources that are incorrectly isolated. Despite their impact, functional interference bugs in OS-level virtualization have received limited attention in part due to the challenges in detecting them. Instead of causing memory errors or crashes, many functional interference bugs involve hard-to-catch logic errors that silently produce semantically incorrect results.
This paper proposes KIT, a dynamic testing framework that discovers functional interference bugs in OS-level virtualization mechanisms, such as Linux namespaces. The key idea of KIT is to detect inter-container functional interference by comparing the system call traces of a container across two executions, where it runs with and without the preceding execution of another container. To achieve high efficiency and accuracy, KIT includes two critical components: an efficient algorithm to generate test cases that exercise inter-container data flows and a system call trace analysis framework that detects functional interference bugs and clusters bug reports. KIT discovered 9 functional interference bugs in Linux kernel 5.13, of which 6 have been confirmed. All bugs are caused by logic errors, showing that this approach is able to detect hard-to-catch semantic bugs.
• Security and privacy → Virtualization and security; • Software and its engineering → Software testing and debugging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers12
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- Pegasus: Transparent and Unified Kernel-Bypass Networking for Fast Local and Remote CommunicationDinglan Peng, Congyu Liu, Tapti Palit, Anjo Vahldiek-Oberwagner et al.EuroSys 2025 · 6 citations
- Snowplow: Effective Kernel Fuzzing with a Learned White-box Test MutatorSishuai Gong, Wang Rui, Deniz Altinbüken, Pedro Fonseca et al.ASPLOS 2025 · 5 citations
- RFCAudit: AI Agent for Auditing Protocol Implementations Against RFC SpecificationsMingwei Zheng, Chengpeng Wang, Xuwei Liu, Jinyao Guo et al.ASE 2025 · 5 citations
- Validating Network Protocol Parsers with Traceable RFC Document InterpretationMingwei Zheng, Danning Xie, Qingkai Shi, Chengpeng Wang et al.ISSTA 2025 · 4 citations
Builds on23
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 131 citations
Related papers
- Uncontained: Uncovering Container Confusion in the Linux KernelJakob Koschel, Pietro Borrello, Daniele Cono D'Elia, Herbert Bos et al.USENIX Security 2023
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang et al.NDSS 2026
- CofferOS: Hardening OS-level Virtualization with RustMinkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park et al.EuroSys 2026
- Concurrency Fuzzing of the Linux Kernel with eBPFJiacheng Xu, Dylan Wolff, Xing Yi Han, Jialin Li et al.USENIX Security 2026
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo et al.USENIX Security 2025
