USENIX Security2026Top-tier venue
CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety Requirements
Hung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang, Kun Sun
Abstract
Rust has emerged as a leading system programming language by providing strong compile-time guarantees for memory safety. However, these guarantees do not extend to unsafe Rust, where developers may bypass compiler checks and inadvertently introduce memory-safety vulnerabilities. Although prior static analyzers have made progress in detecting such bugs, existing approaches are often fragmented: they target specific coding patterns or bug classes without modeling the underlying causes of unsafety. In this paper, we present CULPA, a universal detector for memory-safety bugs in Rust programs. The key insight of CULPA is to detect the root cause of such bugs: the violation of safety requirements in unsafe Rust contexts. To do so, CULPA first transforms the safety requirements in the standard library documentation into machine-executable predicates. Then it constructs the distinct memory segments to comply with safety requirements. Finally, CULPA collects all safety-relevant safeguards to construct the Requirement Graph. Based on the requirement graph traversal, we can determine whether violations inside unsafe blocks can be triggered. CULPA covers existing bug classes addressed by four prior static analyzers and identifies additional memory-safety vulnerabilities beyond their scope. We evaluate CULPA on the top 1,000 Rust packages. CULPA uncovers 55 previously unknown (zero-day) memory-safety bugs, 29 of which have been confirmed by developers. Most of these vulnerabilities are missed by four state-of-the-art Rust static analyzers and one LLM-based tool. To date, we have received five RustSec IDs and one CVE ID.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on15
- Verus: Verifying Rust Programs using Linear Ghost TypesAndrea Lattuada, Travis Hance, Chanhee Cho, Matthias Brun et al.OOPSLA 2023 · 86 citations
- MirChecker: Detecting Bugs in Rust Programs via Static AnalysisZhuohua Li, Jincheng Wang, Mingshen Sun, John C. S. LuiCCS 2021 · 63 citations
- Rudra: Finding Memory Safety Bugs in Rust at the Ecosystem ScaleYechan Bae, Youngsuk Kim, Ammar Askar, Jungwon Lim et al.SOSP 2021 · 61 citations
- Is rust used safely by software developers?Ana Nora Evans, Bradford Campbell, Mary Lou SoffaICSE 2020 · 57 citations
- RustHornBelt: a semantic foundation for functional verification of Rust programs with unsafe codeYusuke Matsushita, Xavier Denis, Jacques-Henri Jourdan, Derek DreyerPLDI 2022 · 44 citations
Related papers
- Rusted Types: Static Detection of Rust Type Confusion BugsZeyang Zhuang, Wei Meng, Michael R. LyuICSE 2026
- Understanding memory and thread safety practices and issues in real-world Rust programsBoqin Qin, Yilun Chen, Zeming Yu, Linhai Song et al.PLDI 2020 · 112 citations
- TYPEPULSE: Detecting Type Confusion Bugs in Rust ProgramsHung-Mao Chen, Xu He, Shu Wang, Xiaokuan Zhang et al.USENIX Security 2025
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 5 citations
- "I wouldn't want my unsafe code to run my pacemaker": An Interview Study on the Use, Comprehension, and Perceived Risks of Unsafe RustSandra Höltervennhoff, Philip Klostermeyer, Noah Wöhler, Yasemin Acar et al.USENIX Security 2023
