OZZ: Identifying Kernel Out-of-Order Concurrency Bugs with In-Vivo Memory Access Reordering
Dae R. Jeong, Yewon Choi, Byoungyoung Lee, Insik Shin, Youngjin Kwon
摘要
Kernel concurrency bugs are notoriously difficult to identify, while their consequences severely threaten the reliability and security of the entire system. Especially in the kernel, developers should consider not only locks but also memory barriers to prevent out-of-order execution from breaking the correctness of concurrent execution. Incorrect use of memory barriers may cause non-intuitive concurrency bugs that manifest due to out-of-order execution, which we refer to as OOO bugs.
This paper aims to identify OOO bugs in the kernel. We devise a mechanism to emulate out-of-order execution while kernel code is executed, called OEMU. Inspired by how a processor reorders memory accesses, OEMU makes the subtle and non-deterministic behavior of out-of-order execution systematically controllable. Based on OEMU, we propose OZZ, a new testing tool designed to effectively identify kernel OOO bugs. The key feature of OZZ is its ability to deterministically control both out-of-order execution and concurrent execution caused by thread interleavings, enabling comprehensive testing of their combined effects. Our evaluation shows that OEMU is effective in reproducing previously-reported kernel OOO bugs, demonstrating its strong capability of controlling out-of-order execution. Furthermore, with OZZ, we identify 11 new OOO bugs in the latest version of the Linux kernel, subsequently confirmed and patched by kernel developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Adjacent Words, Divergent Intents: Jailbreaking Large Language Models via Task ConcurrencyYukun Jiang, Mingjie Li, Michael Backes, Yang ZhangNeurIPS 2025 · 被引用 17 次
- Converos: Practical Model Checking for Verifying Rust OS Kernel ConcurrencyRuize Tang, Minghua Wang, Xudong Sun, Lin Huang 等USENIX ATC 2025 · 被引用 4 次
- Fray: An Efficient General-Purpose Concurrency Testing Platform for the JVMAo Li, Byeongjee Kang, Vasudev Vikram, Isabella Laybourn 等OOPSLA 2025
- DMGuard: Safeguarding Kernels from Physical-Page Use-After-Free VulnerabilitiesJuhee Kim, Jaeyoung Chung, Dae R. Jeong, Byoungyoung LeeUSENIX Security 2026
- SyzParam: Incorporating Runtime Parameters into Kernel Driver FuzzingYue Sun, Yan Kang, Chenggang Wu, Kangjie Lu 等CCS 2025
它引用的顶会 Paper38
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee 等S&P 2019 · 被引用 202 次
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
相关 Paper
- A Comprehensive Study of Concurrency Bugs in the Linux KernelSishuai Gong, Chih-En Lin, Kevin Wu, Edwin Lu 等ICSE 2026 · 被引用 1 次
- OFence: Pairing Barriers to Find Concurrency Bugs in the Linux KernelBaptiste Lepers, Josselin Giet, Willy Zwaenepoel, Julia LawallEuroSys 2023 · 被引用 1 次
- Concurrency Fuzzing of the Linux Kernel with eBPFJiacheng Xu, Dylan Wolff, Xing Yi Han, Jialin Li 等USENIX Security 2026
- Snowboard: Finding Kernel Concurrency Bugs through Systematic Inter-thread Communication AnalysisSishuai Gong, Deniz Altinbüken, Pedro Fonseca, Petros ManiatisSOSP 2021 · 被引用 26 次
- CARDSHARK: Understanding and Stablizing Linux Kernel Concurrency Bugs Against the OddsTianshuo Han, Xiaorui Gong, Jian LiuUSENIX Security 2024 · 被引用 2 次
