S nowplow : Effective Kernel Fuzzing with a Learned White-box Test Mutator
Sishuai Gong, Wang Rui, Deniz Altınbüken, Pedro Fonseca, Petros Maniatis · 2025
Kernel fuzzers rely heavily on program mutation to automatically generate new test programs based on existing ones. In particular, program mutation can alter the test's control and data flow inside the kernel by inserting new system calls, changing the values of call arguments, or performing other program mutations. However, due to the complexity of the kernel code and its user-space interface, finding the effective mutation that can lead to the desired outcome such as increasing the coverage and reaching a target code location is extremely difficult, even with the widespread use of manually-crafted heuristics.