ABCDEFGHIJKLMNOPQRSTUVWXYZAA
1
The performance of Syzkaller, Syzkaller variant, GREBE and GREBE without mutation optimization sampled from Table II. The "SYZ ID" column is the case ID. The "Initial Error Behavior" column indicates the error behavior manifested
in the corresponding bug report. The "Discovered New Error Behaviors" column is the behaviors new discovered. In the “Time” column, T1 represents the amount of hours Syzkaller took, T2 is for Syzkaller’s variant, T3 is for GREBE
without optimization, and T4 stands for GREBE. The dash “-” means the corresponding behavior is not discovered by the corresponding tool.
2
3
4
SYZ IDCritical Structures IdentifiedInitial Error BehaviorDiscovered New Error BehaviorsTime (in hours)
5
T1T2T3T4
6
d2c64e2l2tp_session, l2tp_tunnelkernel BUG at net/l2tp/l2tp core.c:LINE!WARNING: locking bug in do ipv6 setsockopt---0.28
7
WARNING: locking bug in inet autobind---8.05
8
WARNING: locking bug in inet6 bind---3.7
9
WARNING: locking bug in ip6 datagram connect---12.51
10
WARNING: locking bug in sock setsockopt---84.26
11
WARNING: locking bug in do ipv6 getsockopt---116.89
12
WARNING: locking bug in sock bindtoindex---144.36
13
09fc5ecblkpg_partition, block_device
gendisk, hd_struct
KASAN: use-after-free Read in delete partition-----
14
d1baeb1skb_shared_infoBUG: unable to handle kernel paging request in skb release datageneral protection fault in skb release data--23.760.99
15
KASAN: wild-memory-access Read in skb copy ubufs---33.18
16
KASAN: slab-out-of-bounds Write in pskb expand head---46.21
17
8eceafftc_action, tcf_extsWARNING: refcount bug in tcf action putgeneral protection fault in tcf action destroy--1.04148.74
18
KASAN: use-after-free Write in tcindex set parms--6.8943.63
19
KASAN: slab-out-of-bounds Write in tcindex destroy--150.36149.16
20
WARNING in tcf exts destroy--148.950.02
21
KASAN: global-out-of-bounds Read in tcf action destroy--8.28-
22
KASAN: invalid-free in tcf exts destroy--10.36-
23
b4b5c74xt_led_info,
xt_led_info_internal, xt_tgdtor_param
INFO: trying to register non-static key in led tg destroy-----
24
bb7fa48futex_pi_stateWARNING in get pi stateKASAN: use-after-free Read in exit pi state list -2.430.040.08
25
229e0b7delayed_uprobe general protection fault in delayed uprobe removeKASAN: use-after-free Read in delayed uprobe remove--3.836.66
26
KASAN: use-after-free Read in uprobe mmap--12.694.1
27
general protection fault in uprobe mmap---89.49
28
KASAN: use-after-free Read in update ref ctr---157.46
29
6a44063bpf_array, pcpu_chunkBUG: unable to handle kernel paging request in pcpu alloc-----
30
d767177skcipher_walkgeneral protection fault in crypto chacha20 cryptKASAN: stack-out-of-bounds Read in crypto chacha20 crypt-0.55-72.34
31
KASAN: slab-out-of-bounds Read in crypto chacha20 crypt---83.16
32
460cc94fixed_file_data,
fixed_file_table, io_ring_ctx
WARNING: ODEBUG bug in io sqe files unregisterKASAN: use-after-free Read in percpu ref switch to atomic rcu---42.86
33
WARNING in percpu ref exit--8.887.65
34
3a6c997bitmap_ip, bitmap_ip_adt_elem, ip_setKASAN: slab-out-of-bounds Read in bitmap ip addKASAN: slab-out-of-bounds Write in bitmap ip del---8.32
35
KASAN: slab-out-of-bounds Read in bitmap ipmac gc---43.86
36
KASAN: slab-out-of-bounds Read in bitmap ip ext cleanup---118.65
37
KASAN: slab-out-of-bounds Read in bitmap ip test---0.26
38
KASAN: slab-out-of-bounds Read in bitmap ip gc---61.97
39
KASAN: use-after-free Read in bitmap ip ext cleanup---17.31
40
KASAN: slab-out-of-bounds Read in bitmap ip list---0.6
41
KASAN: slab-out-of-bounds Read in bitmap ipmac list---33.83
42
KASAN: use-after-free Read in bitmap ipmac ext cleanup---58.62
43
KASAN: slab-out-of-bounds Read in bitmap ipmac test---49.3
44
2389bfctc_action, tcf_exts,
tcindex_data, tcindex_filter_result
KASAN: slab-out-of-bounds Read in tcf exts destroy-----
45
27ae1aedst_entry, metadata_dst
rcu_cblist, rt6_info, xfrm_dst
KASAN: use-after-free Read in find matchKASAN: use-after-free Read in neigh notify---2.07
46
e4be308crypto_shash,
kdf_sdesc,shash_desc
KASAN: slab-out-of-bounds Write in sha512 finalKASAN: slab-out-of-bounds Write in tgr192 final--2.3114.22
47
KASAN: slab-out-of-bounds Write in tgr160 final--1.433.9
48
KASAN: slab-out-of-bounds Write in crypto sha3 final--2.764.65
49
KASAN: slab-out-of-bounds Write in rmd320 final--1.820.81
50
KASAN: slab-out-of-bounds Write in wp384 final--3.030.19
51
KASAN: slab-out-of-bounds Write in sha512 finup--0.112.84
52
KASAN: slab-out-of-bounds Write in sha1 finup--3.341.8
53
KASAN: slab-out-of-bounds Write in sha1 final--3.7612.46
54
KASAN: slab-out-of-bounds Write in sha256 final--1.0712.75
55
KASAN: slab-out-of-bounds Write in rmd160 final--0.380.48
56
KASAN: slab-out-of-bounds Write in sha256 finup--2.0613
57
f56bbe6iov_iter, qrtr_hdr_v1
qrtr_hdr_v2
general protection fault in qrtr endpoint postKASAN: slab-out-of-bounds Read in qrtr endpoint post--26.0912.25
58
521a764ax25_address, nr_sockWARNING: refcount bug in nr insert socketKASAN: use-after-free Read in release sock0.692.3611.744.39
59
KASAN: use-after-free Read in nr release---20
60
KASAN: use-after-free Read in nr insert socket--0.030.06
61
KASAN: use-after-free Write in nr insert socket---126.82
62
KASAN: use-after-free Read in lock sock nested---18.2
63
7d0275fsk_buff_head, tipc_msg
tipc_sock
WARNING in tipc msg append-----
64
7022420snd_pcm_channel_area,
snd_pcm_oss_file,
snd_pcm_oss_runtime,
snd_pcm_plugin,
snd_pcm_plugin_channel,
snd_pcm_plugin_format,
snd_pcm_runtime,
snd_pcm_substream
KASAN: slab-out-of-bounds Read in default write copy kernelKASAN: slab-out-of-bounds Read in default write copy kernel--3.043.84
65
4cf5ee7vb2_buffer,
vb2_queue, video_device
general protection fault in vb2 mmapKASAN: use-after-free Read in vb2 mmap--8.239.19
66
KASAN: use-after-free in vb2 mmap---138.81
67
502c872netlink_ext_ackgeneral protection fault in netlink ackKASAN: stack-out-of-bounds Read in nla put0.010.010.010.01
68
cbb2898crypto_shash, sctp_endpoint
sctp_sock
KASAN: use-after-free Read in sctp auth freeKASAN: use-after-free Read in sctp auth destroy hmacs--0.020.02
69
5c9918dio_kiocb, wait_queue_entrygeneral protection fault in io poll double wake-----
70
ed6f145vhost_net, vhost_net_virtqueue
vhost_virtqueue, vhost_vring_file
kernel BUG at drivers/vhost/vhost.c:LINE!-----
71
1fd1d44scatter_walk, skcipher_walkgeneral protection fault in scatterwalk copychunksgeneral protection fault in skcipher walk done---0.4
72
badc913QdiscWARNING: refcount bug in qdisc put-----
73
0df4c1avhost_dev,
vhost_net
WARNING in vhost dev cleanupKASAN: use-after-free Read in remove wait queue---5.67
74
KASAN: use-after-free Read in corrupted---54.3
75
KASAN: use-after-free Read in eventfd release---0.13
76
4bf11aaextended_inquiry_info, hci_devKASAN: slab-out-of-bounds Read in hci extended inquiry result evtKASAN: slab-out-of-bounds Read in hci event packet0.02--0.01
77
b7f4861devlink, devlink_health_reporter
nsim_dev, nsim_dev_health
KASAN: use-after-free Read in devlink health reporter destroy-----
78
3b7409frdma_cm_id, rdma_id_private
rdma_ucm_resolve_ip, sockaddr
sockaddr_ib, sockaddr_in
sockaddr_in6, ucma_context
ucma_file
KASAN: use-after-free Read in cma bind portKASAN: use-after-free Read in cma acquire dev---29.79
79
KASAN: use-after-free Read in rdma listen--144.92-
80
27ea7aepde_opener, seq_file
snd_info_buffer, snd_info_private_data
WARNING in snd info get line-----
81
160442ahci_dev, inquiry_info_with_rssiKASAN: slab-out-of-bounds Read in hci inquiry result with rssi evt-----
82
163388ddma_buf, v4l2_fh
v4l2_m2m_ctx
v4l2_m2m_queue_ctx
vb2_buffer, vb2_plane
vb2_queue, vim2m_ctx
vb2_vmalloc_buf
WARNING in dma buf vunmapgeneral protection fault in vb2 queue free--119.9811.03
83
KASAN: null-ptr-deref Read in vb2 vmalloc put--5.689.87
84
WARNING in vb2 warn zero bytesused--68.6714
85
WARNING in vb2 queue cancel--14.3356.83
86
bdeea91aead_instance, crypto_aead
crypto_aead_spawn, crypto_spawn
crypto_type, pcrypt_instance_ctx
WARNING: refcount bug in crypto mod getWARNING: refcount bug in crypto destroy tfm6.692.620.061.25
87
KASAN: use-after-free Read in crypto alg extsize---83.69
88
b9b37a7mousedev_clientBUG: corrupted list in mousedev releaseWARNING: ODEBUG bug in exit to user mode prepare---2.56
89
BUG: corrupted list in mousedev detach client--0.040.02
90
KASAN: use-after-free Read in m oss release---1.63
91
KASAN: use-after-free Read in m oss release file---1.63
92
KASAN: vmalloc-out-of-bounds Write in m format set silence---11.89
93
KASAN: use-after-free Read in task work run---18.85
94
b0e30absmc_sockgeneral protection fault in kernel acceptKASAN: use-after-free Read in kernel accept-0.557.720.49
95
general protection fault in kernel accept-0.030.010.01
96
d5222b3addr_req, rdma_cm_id, ucma_file
rdma_id_private, ucma_context
WARNING: bad unlock balance in ucma event handlerWARNING: bad unlock balance in ucma destroy id--74.343.36
97
general protection fault in rdma listen---22.2
98
KASAN: use-after-free Read in rdma listen31.67-38.8821.69
99
BUG: corrupted list in rdma listen--114.51-
100
de28cb0dst_entry,
neigh_table,
neighbour,
rt6_info
BUG: corrupted list in neigh createBUG: corrupted list in neigh mark dead15.335.90.1510.89