USENIX Security2024Top-tier venue
CARDSHARK: Understanding and Stablizing Linux Kernel Concurrency Bugs Against the Odds
Tianshuo Han, Xiaorui Gong, Jian Liu
Abstract
Concurrency bugs in the Linux kernel are notoriously difficult to reproduce and debug due to their non-deterministic nature. While they bring constant headaches to Linux kernel developers, the reasons behind the non-determinism and how to improve the efficiency in triggering concurrency bugs to ease the debugging process still need to be studied. This work aims to fill the gap. We comprehensively study the concurrency bug stability problem in the Linux kernel, dissect the factors behind the non-determinism, and systematize the insights into a model to explain the non-deterministic nature of concurrency bugs. Based on insights derived from the model, we identify an under-studied factor, named misalignment, which plays a vital role in triggering concurrency bugs. By controlling this factor, we significantly reduce the randomness in the concurrency bug-triggering process. Inspired by this insight, we design a novel technique, named CARDSHARK, that can significantly improve the efficiency in triggering concurrency bugs when kernel instrumentation is possible. A variant of CARDSHARK, named BLIND-SHARK, enables developers to improve efficiency in triggering concurrency bugs without knowing their root causes, making the use of CARDSHARK practical. In our evaluation of 12 real-world concurrency bugs, CARDSHARK and BLINDSHARK significantly reduce the needed time and the number of attempts to trigger concurrency bugs in the Linux kernel. Notably, CARDSHARK can deterministically trigger 10 out of the 12 concurrency bugs with a single attempt. Our evaluation shows that CARDSHARK significantly outperforms existing works in stabilizing concurrency bugs, making it a potential great help to developers in analyzing and fixing concurrency bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fe3f2d25-51ef-436b-a8a8-554c1a57f17eCited by top-tier papers2
- Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata FieldsHao Zhang, Jian Liu, Jie Lu, Shaomin Chen et al.CCS 2025
- Concurrency Fuzzing of the Linux Kernel with eBPFJiacheng Xu, Dylan Wolff, Xing Yi Han, Jialin Li et al.USENIX Security 2026
Builds on8
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes et al.S&P 2018 · 95 citations
- RAProducer: efficiently diagnose and reproduce data race bugs for binaries via trace analysisMing Yuan, Yeseop Lee, Chao Zhang, Yun Li et al.ISSTA 2021 · 7 citations
- Diagnosing Kernel Concurrency Failures with AITIADae R. Jeong, Minkyu Jung, Yoochan Lee, Byoungyoung Lee et al.EuroSys 2023 · 3 citations
- Precise Detection of Kernel Data Races with Probabilistic Lockset AnalysisGabriel Ryan, Abhishek Shah, Dongdong She, Suman JanaS&P 2023
Related papers
- A Comprehensive Study of Concurrency Bugs in the Linux KernelSishuai Gong, Chih-En Lin, Kevin Wu, Edwin Lu et al.ICSE 2026 · 1 citation
- OZZ: Identifying Kernel Out-of-Order Concurrency Bugs with In-Vivo Memory Access ReorderingDae R. Jeong, Yewon Choi, Byoungyoung Lee, Insik Shin et al.SOSP 2024 · 4 citations
- SegFuzz: Segmentizing Thread Interleaving to Discover Kernel Concurrency Bugs through FuzzingDae R. Jeong, Byoungyoung Lee, Insik Shin, Youngjin KwonS&P 2023
- DDRace: Finding Concurrency UAF Vulnerabilities in Linux Drivers with Directed FuzzingMing Yuan, Bodong Zhao, Penghui Li, Jiashuo Liang et al.USENIX Security 2023
- OFence: Pairing Barriers to Find Concurrency Bugs in the Linux KernelBaptiste Lepers, Josselin Giet, Willy Zwaenepoel, Julia LawallEuroSys 2023 · 1 citation
