Inferring 1-Minimal Trigger Configurations for Assessing Linux Kernel CVE Triggerability
Tongjie Wei, Peng Zhang, Zhiwen Hu, Xupu Hu, Chen Lyu, Gangyan Zeng
摘要
Vendors assessing Linux kernel CVEs need to know whether a bug is triggerable under production-tailored configurations, not merely whether a version is affected, yet upstream reproducers and vulnerability databases rarely provide configuration-level context. We study minimal trigger-configuration inference: given a CVE entry and a target kernel version (optionally a baseline .config), we synthesize a Kconfig-satisfiable option set that remains effective after make olddefconfig and, when a reproducer is available, still triggers under a specified evaluation protocol; we then prune it to a 1-minimal (subset-minimal) boundary for evaluation. Our framework FCC links vulnerability cues to build-system symbols, completes implicit prerequisites under olddefconfig feedback to avoid silent rollback, and performs runtime-validated minimization guided by dependency topology. We evaluate on KernJC and KernelCTF, totaling 88 CVEs across multiple kernel versions. On the 88-CVE set, FCC improves the post-make olddefconfig configuration success rate from 62.5% (55/88) to 96.6% (85/88) over an olddef-only injection baseline; on the KernJC set, FCC reduces the average candidate set size by 78.7% compared to KernJC (Avg. 14.72 vs. 69.00 options per CVE). A stage-wise analysis of time and token costs shows that Stage I dominates overhead, while CVE-focused evidence selection substantially reduces this cost. By returning an effective and auditable 1-minimal configuration boundary, FCC helps vendors scope triggerability against their deployment configurations with a clear, tool-supported decision line.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Large Language Models are Few-shot Testers: Exploring LLM-based General Bug ReproductionSungmin Kang, Juyeon Yoon, Shin YooICSE 2023 · 被引用 163 次
- Prompting Is All You Need: Automated Android Bug Replay with Large Language ModelsSidong Feng, Chunyang ChenICSE 2024 · 被引用 143 次
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu 等USENIX Security 2018 · 被引用 138 次
- Your Exploit is Mine: Automatic Shellcode Transplant for Remote ExploitsTiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, David BrumleyS&P 2017 · 被引用 56 次
- Finding broken Linux configuration specifications by statically analyzing the Kconfig languageJeho Oh, Necip Fazil Yildiran, Julian Braha, Paul GazzilloFSE 2021 · 被引用 46 次
相关 Paper
- Automated Detection of Configuration-Specific Security Vulnerabilities via Patch AnalysisFelipe de Sant'Anna Paixão, Joanna C. S. Santos, Paulo Anselmo da Mota Silveira Neto, Daniel Sadoc Menasché 等FSE 2026
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou 等USENIX Security 2024 · 被引用 7 次
- Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule ComparisonQiushi Wu, Yang He, Stephen McCamant, Kangjie LuNDSS 2020
- KernelRCA: Facilitating Root Cause Analysis of Memory Corruptions in Linux Kernel with Contextual Causality ChainKangzheng Gu, Yifan Zhang, Yuan Zhang, Min YangUSENIX Security 2026
- KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write VulnerabilitiesWeiteng Chen, Xiaochen Zou, Guoren Li, Zhiyun QianUSENIX Security 2020
