Toss a Fault to BpfChecker: Revealing Implementation Flaws for eBPF runtimes with Differential Fuzzing
Chaoyuan Peng, Muhui Jiang, Lei Wu, Yajin Zhou
摘要
eBPF is a revolutionary technology that can run sandboxed programs in a privileged context and has an extensive range of applications, such as network monitoring on Linux kernel, denial-of-service protection on Windows, and the execution mechanism of smart contracts on blockchain. However, implementation flaws in eBPF have broad-reaching impact and serious consequences. Prior studies primarily focus on the memory safety of the eBPF runtimes, but few can detect implementation flaws (i.e., whether the implementation is correct). Meanwhile, existing implementation flaws detecting methods predominantly address bugs in the verifier, neglecting bugs in other components (i.e., the interpreter and the JIT compiler). In this paper, we present BpfChecker, a differential fuzzing framework to detect implementation flaws in the eBPF runtimes. It utilizes eBPF programs as input, performing differential testing for the critical states across various eBPF runtimes to uncover implementation flaws. To enhance the semantics of generated programs, we devise a lightweight intermediate representation and perform constrained mutations under the guidance of error messages. We have implemented a prototype of BpfChecker and extensively evaluated it on the three eBPF runtimes (i.e., Solana rBPF, vanilla rBPF, Windows eBPF). As a result, we have uncovered 28 new implementation flaws, received 2 CVEs and 800,000 bounty with developers' acknowledgment. More importantly, 2 of the newly found bugs can be used to create divergences in the execution layer of the Solana network.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper4
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等S&P 2025
- Soleker: Uncovering Vulnerabilities in Solana Smart ContractsKunsong Zhao, Yunpeng Tian, Zuchao Ma, Xiapu LuoASE 2025
- Approximation Enforced Execution of Untrusted Linux Kernel ExtensionsHao Sun, Zhendong SuUSENIX Security 2025
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided InstrumentationWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Ping Fan Ke 等SOSP 2026
相关 Paper
- BRF: Fuzzing the eBPF RuntimeHsin-Wei Hung, Ardalan Amiri SaniFSE 2024 · 被引用 8 次
- RPCSpecter: Detecting Blockchain RPC Bugs through a Specification-Driven, Constraint-Aware Fuzzing ApproachYuming Xiao, Yuhong Nan, Zhijie Zhong, Mingxi Ye 等ISSTA 2026
- A Complete Formal Semantics of eBPF Instruction Set Architecture for SolanaShenghao Yuan, Zhuoruo Zhang, Jiayi Lu, David Sanán 等OOPSLA 2025 · 被引用 3 次
- Validating the eBPF Verifier via State EmbeddingHao Sun, Zhendong SuOSDI 2024 · 被引用 18 次
- VEP: A Two-stage Verification Toolchain for Full eBPF ProgrammabilityXiwei Wu, Yueyang Feng, Tianyi Huang, Xiaoyang Lu 等NSDI 2025 · 被引用 8 次
