To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO Devices
Sönke Huster, Matthias Hollick, Jiska Classen
Abstract
The security of Linux kernel interfaces is paramount in preventing over-the-air, proximity, or other network attacks. The Linux kernel is fuzzed continuously to detect newly introduced bugs. Despite their long runtime, existing fuzzers fail to detect critical bugs, as they are unaware of physical device semantics and difficult to adapt to new devices. This paper proposes a novel fuzzer called VirtFuzz, which is based on Virtual I/O (VirtIO) device drivers. A proxy mechanism enables data collection from physical device interaction. These collected inputs are then used to fuzz through a virtual device. Using our universal VirtIO device, VirtFuzz is generic and can be easily adapted to various Linux VirtIO kernel drivers and their related subsystems. We use this approach to fuzz the Linux Bluetooth and Wireless LAN (WLAN) stacks. To demonstrate the adaptability of our approach, we additionally provide implementations to fuzz the networking and input stack. We find 31 new, manually confirmed bugs, with 6 Common Vulnerabilities and Exposuress (CVEs) assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ee2e9290-fa61-4c4c-8ca2-730bebcf94d0Cited by top-tier papers3
- BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol StacksWei-Che Kao, Yen-Chia Chen, Yu-Sheng Lin, Yu-Cheng Yang et al.USENIX Security 2025
- NetPanic: the Attack Surface You Can't SyscallTianshuo Han, Zong Cao, Zhen Dong, Xiapu Luo et al.S&P 2026
- SyzParam: Incorporating Runtime Parameters into Kernel Driver FuzzingYue Sun, Yan Kang, Chenggang Wu, Kangjie Lu et al.CCS 2025
Builds on38
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
Related papers
- DevFuzz: Automatic Device Model-Guided Device Driver FuzzingYilun Wu, Tong Zhang, Changhee Jung, Dongyoon LeeS&P 2023
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- DROIDFUZZ: Proprietary Driver Fuzzing for Embedded Android DevicesJianzhong Liu, Yuheng Shen, Yifei Chu, Qiang Zhang et al.DAC 2025
- PrIntFuzz: fuzzing Linux drivers via automated virtual device simulationZheyu Ma, Bodong Zhao, Letu Ren, Zheming Li et al.ISSTA 2022 · 23 citations
- USBFuzz: A Framework for Fuzzing USB Drivers by Device EmulationHui Peng, Mathias PayerUSENIX Security 2020
