LinKRID: Vetting Imbalance Reference Counting in Linux kernel with Symbolic Execution
Jian Liu, Lin Yi, Weiteng Chen, Chengyu Song, Zhiyun Qian, Qiuping Yi
摘要
Linux kernel employs reference counters, which record the number of references to a shared kernel object, to track its lifecycle and prevent memory errors like use-after-free. However, the usage of reference counters can be tricky and often error-prone, especially considering unique kernel conventions of managing reference counters (e.g., external vs. internal reference counters). In this paper, we aim to automatically discover incorrect usage of reference counters, overcoming two key challenges: (1) scalability and (2) the aforementioned unique kernel conventions. Specifically, we develop a tiered program analysis based solution to efficiently and precisely check the imbalances between the change in the actual number of references and the corresponding reference counter. We apply our tool to the 4.14.0 kernel (with allyesconfig) and find 118 bugs, out of which 87 are new. The result shows our tool is scalable and effective.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong 等CCS 2023 · 被引用 25 次
- SCAVY: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege EscalationErin Avllazagaj, Yonghwi Kwon, Tudor DumitrasUSENIX Security 2024 · 被引用 7 次
- Towards More Accurate Static Analysis for Taint-Style Bug Detection in Linux KernelHaonan Li, Hang Zhang, Kexin Pei, Zhiyun QianASE 2025 · 被引用 5 次
- CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelShuangpeng Bai, Zhechang Zhang, Hong HuCCS 2024 · 被引用 4 次
- One Simple API Can Cause Hundreds of Bugs An Analysis of Refcounting Bugs in All Modern Linux KernelsLiang He, Purui Su, Chao Zhang, Yan Cai 等SOSP 2023 · 被引用 3 次
它引用的顶会 Paper7
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss 等CCS 2016 · 被引用 381 次
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris 等NDSS 2016 · 被引用 141 次
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing 等USENIX Security 2018 · 被引用 124 次
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
相关 Paper
- Detecting Kernel Refcount Bugs with Two-Dimensional Consistency CheckingXin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu 等USENIX Security 2021 · 被引用 26 次
- FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on BinariesLiang He, Hong Hu, Purui Su, Yan Cai 等USENIX Security 2022
- Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux KernelYizhuo Zhai, Yu Hao, Zheng Zhang, Weiteng Chen 等NDSS 2022
- Detecting Memory-Related Bugs by Tracking Heap Memory Management of C++ Smart PointersXutong Ma, Jiwei Yan, Wei Wang, Jun Yan 等ASE 2021 · 被引用 10 次
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
