An Exploration of Fuzzing for Discovering Use-After-Free Vulnerabilities
Zeyu Chen, Jidong Xiao, Angelos Stavrou, Haining Wang · 2024
Fuzzing has gained considerable success as a dynamic testing technique that rapidly generates a large number of faulty inputs to effectively discover bugs. However, the relationship between the inherent randomness of fuzzing and use-after-free (UAF) vulnerabilities remains unclear. Can fuzzing efficiently identify UAF instances with specific patterns and characteristics? Since UAF involves multiple stages, such as memory allocation, memory deallocation, and memory dereference, does the efficiency of fuzzing depend on the code scope of UAF, making it more challenging to identify bugs with larger code scopes? What characteristics of UAF make it harder for fuzzers to detect, such as non-deterministic bugs? Additionally, fuzzing relies on indicators like crashes to find bugs, but UAF does not always result in a crash. Are auxiliary tools like address sanitizers (ASan) necessary to assist fuzzers in identifying UAF, and what are the associated costs? In this study, we explore the capabilities of fuzzing techniques in discovering UAF vulnerabilities. We attempt to answer these questions above by conducting a series of experiments based on existing fuzzers, and finally, we provide practical guidelines to enhance UAF detection with fuzzers.