USENIX Security2026Top-tier venue
Meerkat: Pushing the Practical Limits of Dynamic Bisection with PoC Mutation
Joseph Bursey, Christoph Sendner, Ardalan Amiri Sani, Zhiyun Qian
Abstract
Once a Linux kernel bug is identified, the developers perform the difficult task of patching it. Triage tools such as Syz-bisect provide a form of root cause analysis called bisection, which systematically checks historical kernel commits for the presence of the bug until it determines the Bug-Introducing Commit (BiC). Unfortunately, Syz-bisect correctly identifies the BiC for only 35% of bugs. In order to improve Syz-bisect while remaining within its time and resource constraints, we identify three areas where Syz-bisect could be improved: bug deduplication, the use of all available PoCs, and PoC mutation. Our solution Meerkat is the first dynamic bisection tool to apply scalable PoC mutation, improving over Syz-bisect by 64%. Through an in-depth manual analysis of Meerkat's bisection results, we find that dynamic bisection is critically limited by bug detectors changing with kernel versions, changes near the buggy code, and unrelated bugs that block dynamic analysis. Based on the nature of these issues, we argue that Meerkat is approaching the practical limits of what is possible with dynamic bisection in the real world. Furthermore, we correct the ground truth for 13 bugs, thus improving the dataset for future research.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eabf9205-6c7c-4286-8609-99f85f785fa8Builds on29
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- NEUZZ: Efficient Fuzzing with Neural Program SmoothingDongdong She, Kexin Pei, Dave Epstein, Junfeng Yang et al.S&P 2019 · 220 citations
Related papers
- SyzBridge: Bridging the Gap in Exploitability Assessment of Linux Kernel Bugs in the Linux EcosystemXiaochen Zou, Yu Hao, Zheng Zhang, Juefei Pu et al.NDSS 2024
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou et al.USENIX Security 2024 · 7 citations
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong et al.CCS 2023 · 25 citations
- UBITect: a precise and scalable method to detect use-before-initialization bugs in Linux kernelYizhuo Zhai, Yu Hao, Hang Zhang, Daimeng Wang et al.FSE 2020 · 34 citations
- SemBIC: Semantic-Aware Identification of Bug-Inducing CommitsXiao Chen, Hengcheng Zhu, Jialun Cao, Ming Wen et al.FSE 2025 · 1 citation
