Precise Detection of Kernel Data Races with Probabilistic Lockset Analysis
Gabriel Ryan, Abhishek Shah, Dongdong She, Suman Jana
摘要
Finding data races is critical for ensuring security in modern kernel development. However, finding data races in the kernel is challenging because it requires jointly searching over possible combinations of system calls and concurrent execution schedules. Kernel race testing systems typically perform this search by executing groups of fuzzer seeds from a corpus and applying a combination of schedule fuzzing and dynamic race prediction on traces. However, predicting which combinations of seeds can expose races in the kernel is difficult as fuzzer seeds will usually follow different execution paths when executed concurrently due to inter-thread communications and synchronization.To address this challenge, we introduce a new analysis for kernel race prediction, Probabilistic Lockset Analysis (PLA) that addresses the challenges posed by race prediction for the kernel. PLA leverages the observation that system calls almost always perform certain memory accesses to shared memory to perform their function. PLA uses randomized concurrent trace sampling to identify memory accesses that are performed consistently and estimates the probability of races between them subject to kernel lock synchronization. By prioritizing high probability races, PLA is able to make accurate predictions.We evaluate PLA against comparable kernel race testing methods and show it finds races at a 3× higher rate over 24 hours. We use PLA to find 183 races in linux kernel v5.18-rc5, including 102 harmful races. PLA is able to find races that have severe security impact in heavily tested core kernel modules, including use-after-free in memory management, OOB write in network cryptography, and leaking kernel heap memory information. Some of these vulnerabilities have been overlooking by existing systems for years: one of the races found by PLA involving an OOB write has been present in the kernel since 2013 (version v3.14-rc1) and has been designated a high severity CVE.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- LR-Miner: Static Race Detection in OS Kernels by Mining Locking RulesTuo Li, Jia-Ju Bai, Gui-Dong Han, Shi-Min HuUSENIX Security 2024 · 被引用 6 次
- CARDSHARK: Understanding and Stablizing Linux Kernel Concurrency Bugs Against the OddsTianshuo Han, Xiaorui Gong, Jian LiuUSENIX Security 2024 · 被引用 2 次
- SyzParam: Incorporating Runtime Parameters into Kernel Driver FuzzingYue Sun, Yan Kang, Chenggang Wu, Kangjie Lu 等CCS 2025
- Static Detection of TOCTOU Bugs Caused by Kernel RacesGui-Dong Han, Jia-Ju Bai, Qiu-Ji Chen, Jiqiang LuUSENIX Security 2026
- Multi-stage On-Demand Program Slicing for Modular Analysis of Multi-threaded ProgramsJiawei Yang, Xiao Cheng, Jiawei Wang, Xiapu Luo 等ISSTA 2026
它引用的顶会 Paper8
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee 等S&P 2019 · 被引用 202 次
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 被引用 131 次
- Fast, sound, and effectively complete dynamic race predictionAndreas PavlogiannisPOPL 2020 · 被引用 46 次
- ExpRace: Exploiting Kernel Races through Raising InterruptsYoochan Lee, Changwoo Min, Byoungyoung LeeUSENIX Security 2021 · 被引用 40 次
- Optimal prediction of synchronization-preserving racesUmang Mathur, Andreas Pavlogiannis, Mahesh ViswanathanPOPL 2021 · 被引用 36 次
相关 Paper
- GhostRace: Exploiting and Mitigating Speculative Race ConditionsHany Ragab, Andrea Mambretti, Anil Kurmus, Cristiano GiuffridaUSENIX Security 2024 · 被引用 10 次
- DDRace: Finding Concurrency UAF Vulnerabilities in Linux Drivers with Directed FuzzingMing Yuan, Bodong Zhao, Penghui Li, Jiashuo Liang 等USENIX Security 2023
- A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel FuzzingSanan Hasanov, Stefan Nagy, Paul GazzilloICSE 2025 · 被引用 6 次
- Accurate Data Race Prediction in the Linux Kernel through Sparse Fourier LearningGabriel Ryan, Burcu Cetin, Yongwhan Lim, Suman JanaOOPSLA 2024 · 被引用 2 次
- CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelShuangpeng Bai, Zhechang Zhang, Hong HuCCS 2024 · 被引用 4 次
