Lune

USENIX Security2024顶会

OptFuzz: Optimization Path Guided Fuzzing for JavaScript JIT Compilers

Jiming Wang, Yan Kang, Chenggang Wu, Yuhao Hu, Yue Sun, Jikai Ren, Yuanming Lai, Mengyao Xie, Charles Zhang, Tao Li, Zhe Wang

出版方
2024年份
7被引次数
5顶会引用

摘要

Just-In-Time (JIT) compiler is a core component of JavaScript engines, which takes a snippet of JavaScript code as input and applies a series of optimization passes on it and then transforms it to machine code. The optimization passes often have some assumptions (e.g., variable types) on the target JavaScript code, and therefore will yield vulnerabilities if the assumptions do not hold. To discover such bugs, it is essential to thoroughly test different optimization passes, but previous work fails to do so and mainly focused on exploring code coverage. In this paper, we present the first optimization path guided fuzzing solution for JavaScript JIT compilers, namely OptFuzz, which focuses on exploring optimization path coverage. Specifically, we utilize an optimization trunk path metric to approximate the optimization path coverage, and use it as a feedback to guide seed preservation and seed scheduling of the fuzzing process. We have implemented a prototype of OptFuzz and evaluated it on 4 mainstream JavaScript engines. On earlier versions of JavaScript engines, OptFuzz found several times more bugs than baseline solutions. On the latest JavaScript engines, OptFuzz discovered 36 unknown bugs, while baseline solutions found none. Table 1: Vulnerabilities in different optimizations. Category Vulnerability Description Instruction CVE-2019-5857 Error in comparison of -0 and null. CVE-2021-30598 Invalid right shift operation optimization. CVE-2021-30599 Wrong optimization of bitfield checks. CVE-2019-1366 Error in handle opcode Decr_A and Sub_A. Loop CVE-2019-8518 wrong hoisting GetByVal leading to OOB. CVE-2019-8623 LICM leaves stack variable uninitialized. CVE-2019-8671 LICM leaves object property access unguarded. CVE-2020-0828 Type confusion when hoisting variable fails. Function CVE-2018-4233 Type confusion caused by abstract interpreter. CVE-2020-9802 Integer range optimization error caused by CSE. Bug240720 The result of integer range analysis is incorrect. CVE-2019-9810 Incorrect alias information leading to OOB. CVE-2019-17026 Incorrect alias information leading to OOB. CVE-2019-26950 UAF caused by wrong side-effect analysis. CVE-2021-21230 Incorrect range information.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper5

问问它们各自怎么用它

它引用的顶会 Paper18

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖