RustGo: Fairly Directed Greybox Fuzzing for Enforcing Rust Memory Safety
Dongyeon Yu, Jiun Min, Yewan Na, Mijung Kim, Taegyu Kim, Yuseok Jeon
Abstract
RustGo Artifacts This Zenodo record contains the artifacts for RustGo: Fairly Directed Greybox Fuzzing for Enforcing Rust Memory Safety, evaluated as part of the ACM CCS 2026 Artifact Evaluation. Abstract Rust is a popular systems programming language that provides strong memory safety with low performance overhead. While Rust enforces memory safety through strict policies such as ownership, memory bugs can still occur in unsafe-related Rust code, where these policies are not fully enforced. Although unsafe Rust code accounts for only a small portion of an entire program (e.g., 10%), existing approaches fuzz the entire program—including safe Rust code whose memory safety is already enforced by the Rust compiler—resulting in inefficient use of fuzzing resources. In this paper, we propose RustGo, the first Rust-directed greybox fuzzer that effectively and fairly focuses on code regions that may contain memory bugs. RustGo automatically identifies potential memory-bug targets and accurately prunes paths irrelevant to each target using Rust-specific static analysis. For each identified target, RustGo maintains an independent fuzzing state and applies dynamic pruning to achieve balanced and focused fuzzing. We evaluate RustGo on various real-world Rust applications. On average, RustGo prunes 78.49% of irrelevant paths, reaches targets ×2.09 to ×5.08 faster than existing fuzzers, and identifies 13 previously unknown bugs, including six assigned RUSTSEC IDs and one assigned CVE ID.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 96e0c8dd-b9d6-4e6a-95a9-a8902e0afcf2Builds on30
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen et al.CCS 2018 · 335 citations
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao et al.S&P 2022 · 139 citations
- Constraint-guided Directed Greybox FuzzingGwangmu Lee, Woochul Shim, Byoungyoung LeeUSENIX Security 2021 · 99 citations
Related papers
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 5 citations
- RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of RustKyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim et al.USENIX Security 2024 · 7 citations
- Rudra: Finding Memory Safety Bugs in Rust at the Ecosystem ScaleYechan Bae, Youngsuk Kim, Ammar Askar, Jungwon Lim et al.SOSP 2021 · 61 citations
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 44 citations
- CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety RequirementsHung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang et al.USENIX Security 2026
