Don't Look UB: Exposing Sanitizer-Eliding Compiler Optimizations
Raphael Isemann, Cristiano Giuffrida, Herbert Bos, Erik van der Kouwe, Klaus von Gleissenthall
摘要
Sanitizers are widely used compiler features that detect undefined behavior and resulting vulnerabilities by injecting runtime checks into programs. For better performance, sanitizers are often used in conjunction with optimization passes. But doing so combines two compiler features with conflicting objectives. While sanitizers want to expose undefined behavior, optimizers often exploit these same properties for performance. In this paper, we show that this clash can have serious consequences: optimizations can remove sanitizer failures, thereby hiding the presence of bugs or even introducing new ones. We present LookUB, a differential-testing based framework for finding optimizer transformations that elide sanitizer failures. We used our method to find 17 such sanitizer-eliding optimizations in Clang. Next, we used static analysis and fuzzing to search for bugs in open-source projects that were previously hidden due to sanitizer-eliding optimizations. This led us to discover 20 new bugs in Linux Containers, libmpeg2, NTFS-3G, and WINE. Finally, we present an effective mitigation strategy based on a customization of the Clang optimizer with an overhead increase of 4%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Boosting Compiler Testing by Injecting Real-World CodeShaohua Li, Theodoros Theodoridis, Zhendong SuPLDI 2024 · 被引用 24 次
- Formal Mechanised Semantics of CHERI C: Capabilities, Undefined Behaviour, and ProvenanceVadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke 等ASPLOS 2024 · 被引用 6 次
- Exploiting Undefined Behavior in C/C++ Programs for Optimization: A Study on the Performance ImpactLucian Popescu, Nuno P. LopesPLDI 2025 · 被引用 2 次
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
它引用的顶会 Paper6
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- Random testing for C and C++ compilers with YARPGenVsevolod Livinskii, Dmitry Babokin, John RegehrOOPSLA 2020 · 被引用 140 次
- FuZZan: Efficient Sanitizer Metadata Design for FuzzingYuseok Jeon, Wookhyun Han, Nathan Burow, Mathias PayerUSENIX ATC 2020 · 被引用 52 次
- SANRAZOR: Reducing Redundant Sanitizer Checks in C/C++ ProgramsJiang Zhang, Shuai Wang, Manuel Rigger, Pinjia He 等OSDI 2021 · 被引用 38 次
- Who's debugging the debuggers? exposing debug information bugs in optimized binariesGiuseppe Antonio Di Luna, Davide Italiano, Luca Massarelli, Sebastian Österlund 等ASPLOS 2021 · 被引用 32 次
相关 Paper
- UBFuzz: Finding Bugs in Sanitizer ImplementationsShaohua Li, Zhendong SuASPLOS 2024 · 被引用 8 次
- Sand: Decoupling Sanitization from Fuzzing for Low OverheadZiqiao Kong, Shaohua Li, Heqing Huang, Zhendong SuICSE 2025 · 被引用 1 次
- CombiSan: Unifying Software Sanitizers for Comprehensive FuzzingMatteo Marini, Floris Gorter, Daniele Cono D'Elia, Cristiano GiuffridaUSENIX Security 2026
- Finding Unstable Code via Compiler-Driven Differential TestingShaohua Li, Zhendong SuASPLOS 2023 · 被引用 19 次
- Optimization-Directed Compiler Fuzzing for Continuous Translation ValidationJaeseong Kwon, Bongjun Jang, Juneyoung Lee, Kihong HeoPLDI 2025 · 被引用 5 次
