UBFuzz: Finding Bugs in Sanitizer Implementations
Shaohua Li, Zhendong Su
Abstract
In this paper, we propose a testing framework for validating sanitizer implementations in compilers. Our core components are (1) a program generator specifically designed for producing programs containing undefined behavior (UB), and (2) a novel test oracle for sanitizer testing. The program generator employs Shadow Statement Insertion, a general and effective approach for introducing UB into a valid seed program. The generated UB programs are subsequently utilized for differential testing of multiple sanitizer implementations. Nevertheless, discrepant sanitizer reports may stem from either compiler optimization or sanitizer bugs. To accurately determine if a discrepancy is caused by sanitizer bugs, we introduce a new test oracle called crash-site mapping.
We have incorporated our techniques into UBfuzz, a practical tool for testing sanitizers. Over a five-month testing period, UBfuzz successfully found 31 bugs in both GCC and LLVM sanitizers. These bugs reveal the serious false negative problems in sanitizers, where certain UBs in programs went unreported. This research paves the way for further investigation in this crucial area of study.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db9b6df2-0838-4e03-8033-d5e94a8a98bfCited by top-tier papers10
- Boosting Compiler Testing by Injecting Real-World CodeShaohua Li, Theodoros Theodoridis, Zhendong SuPLDI 2024 · 24 citations
- Unveiling Compiler Faults via Attribute-Guided Compilation Space ExplorationJiangchang Wu, Yibiao Yang, Maolin Sun, Yuming ZhouUSENIX ATC 2025 · 6 citations
- Optimization-Directed Compiler Fuzzing for Continuous Translation ValidationJaeseong Kwon, Bongjun Jang, Juneyoung Lee, Kihong HeoPLDI 2025 · 5 citations
- Interleaving Large Language Models for Compiler TestingYunbo Ni, Shaohua LiOOPSLA 2025 · 4 citations
- Janus: Detecting Rendering Bugs in Web Browsers via Visual Delta ConsistencyChijin Zhou, Quan Zhang, Bingzhou Qian, Yu JiangICSE 2025 · 2 citations
Builds on10
- Random testing for C and C++ compilers with YARPGenVsevolod Livinskii, Dmitry Babokin, John RegehrOOPSLA 2020 · 140 citations
- FuZZan: Efficient Sanitizer Metadata Design for FuzzingYuseok Jeon, Wookhyun Han, Nathan Burow, Mathias PayerUSENIX ATC 2020 · 52 citations
- Finding missed optimizations through the lens of dead code eliminationTheodoros Theodoridis, Manuel Rigger, Zhendong SuASPLOS 2022 · 48 citations
- SANRAZOR: Reducing Redundant Sanitizer Checks in C/C++ ProgramsJiang Zhang, Shuai Wang, Manuel Rigger, Pinjia He et al.OSDI 2021 · 38 citations
- Debug information validation for optimized codeYuanbo Li, Shuo Ding, Qirun Zhang, Davide ItalianoPLDI 2020 · 30 citations
Related papers
- Don't Look UB: Exposing Sanitizer-Eliding Compiler OptimizationsRaphael Isemann, Cristiano Giuffrida, Herbert Bos, Erik van der Kouwe et al.PLDI 2023 · 5 citations
- CombiSan: Unifying Software Sanitizers for Comprehensive FuzzingMatteo Marini, Floris Gorter, Daniele Cono D'Elia, Cristiano GiuffridaUSENIX Security 2026
- Finding Unstable Code via Compiler-Driven Differential TestingShaohua Li, Zhendong SuASPLOS 2023 · 19 citations
- Sand: Decoupling Sanitization from Fuzzing for Low OverheadZiqiao Kong, Shaohua Li, Heqing Huang, Zhendong SuICSE 2025 · 1 citation
- Evaluating the Effectiveness of Memory Safety SanitizersEmanuel Q. Vintila, Philipp Zieris, Julian HorschS&P 2025
