To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO Devices

Jan Sönke Huster, Matthias Hollick, Jiska Classen

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 5

Overview

In a compelling presentation at IEEE S&P, Jan Sönke Huster, alongside Matthias Hollick and Jiska Classen, unveiled "To Boldly Go Where No Fuzzer Has Gone Before," a groundbreaking paper detailing a novel fuzzing framework designed to uncover vulnerabilities in Linux's wireless communication stacks. The talk introduces "Verf" (derived from VirtIO fuzzer), a custom fuzzer that leverages VirtIO devices within a QEMU virtualized environment to achieve unprecedented depth and authenticity in testing critical kernel components. The research highlights a significant blind spot in existing security testing methodologies for wireless subsystems, demonstrating Verf's capability to penetrate previously untouched areas of the Linux kernel.

Watch on YouTube

Visual summary for To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO Devices by Jan Sönke Huster, Matthias Hollick, Jiska Classen
Visual summary for To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO Devices by Jan Sönke Huster, Matthias Hollick, Jiska Classen

Key moments

  1. 0:00 Introduction and successful fuzzer results
  2. 1:50 Key design goals for their new fuzzer
  3. 2:50 Leveraging VirtIO devices for fuzzing
  4. 3:50 Their innovative Universal VirtIO Device
  5. 5:20 Fuzzer architecture: KCOV, shared memory, LibAFL
  6. 7:00 Critical Wi-Fi vulnerabilities and CVEs found

To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO Devices

Speakers: Jan Sönke Huster; Matthias Hollick; Jiska Classen

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=qOtW3lffueg

Overview

In a compelling presentation at IEEE S&P, Jan Sönke Huster, alongside Matthias Hollick and Jiska Classen, unveiled "To Boldly Go Where No Fuzzer Has Gone Before," a groundbreaking paper detailing a novel fuzzing framework designed to uncover vulnerabilities in Linux's wireless communication stacks. The talk introduces "Verf" (derived from VirtIO fuzzer), a custom fuzzer that leverages VirtIO devices within a QEMU virtualized environment to achieve unprecedented depth and authenticity in testing critical kernel components. The research highlights a significant blind spot in existing security testing methodologies for wireless subsystems, demonstrating Verf's capability to penetrate previously untouched areas of the Linux kernel.

The core innovation lies in Verf's ability to present itself as a standard hardware device to the guest operating system, while in reality, it acts as a conduit for meticulously crafted and mutated inputs. This approach not only facilitates deep kernel coverage but also allows for the use of real-world network traffic as initial fuzzing seeds, enhancing the relevance and effectiveness of the testing process. The work is particularly impactful due to the discovery of numerous severe, remotely exploitable vulnerabilities in both the Wi-Fi and Bluetooth stacks, many of which require no user interaction and affect a wide range of devices, including Android.

The significance of this research cannot be overstated. Wireless communication stacks are fundamental to modern computing, processing untrusted data from the airwaves. Vulnerabilities in these layers can lead to widespread compromise, denial of service, or even remote code execution without any user interaction, as demonstrated by the Wi-Fi Beacon frame vulnerabilities found. Verf's success underscores the critical need for specialized, authentic, and deeply integrated fuzzing solutions to secure these pervasive and high-risk components of the operating system.

Background

▶ Watch: Introduction and successful fuzzer results (0:00)

Fuzzing has emerged as one of the most effective techniques for discovering software vulnerabilities. At its core, fuzzing involves feeding a program with a large volume of malformed or unexpected inputs in an automated fashion, monitoring for crashes, anomalies, or other indications of security flaws. A typical fuzzing loop consists of selecting an input from a seed corpus, mutating it (e.g., bit flips, byte removals, combining inputs), feeding the mutated input to the target, observing its execution (e.g., for crashes or coverage improvements), and saving inputs that yield new code paths or trigger crashes. This iterative process, often running thousands of times per second, aims to exhaustively explore the program's state space.

Despite the widespread adoption of fuzzing for the Linux kernel, the speakers identified several limitations with existing solutions, particularly concerning wireless subsystems. Their primary design goals for Verf were depth, authenticity, and extensibility. They observed that crucial parts of the wireless kernel components were not adequately covered by current fuzzers, leaving potential attack surfaces unexplored. Furthermore, they believed that starting the fuzzing process with authentic, real-world inputs could significantly improve the quality and relevance of the discovered bugs. Finally, they aimed to create a fuzzer that was easily adaptable to different interfaces and new targets, streamlining the process of adding new subsystems for testing.

The chosen solution for achieving these goals was to leverage VirtIO. VirtIO is a standardized interface for paravirtualized devices, designed to allow guest operating systems in virtual machines (VMs) to interact efficiently with hypervisor-managed hardware. From the perspective of a guest OS, VirtIO devices appear like standard physical hardware (e.g., network cards, block devices), allowing the guest to use standard drivers and discovery mechanisms. This abstraction provides a powerful mechanism for injecting inputs directly into the kernel's device drivers, bypassing complex hardware interactions and offering a stable, controllable environment for fuzzing. By building a custom VirtIO device within the hypervisor, Verf could simulate various wireless hardware, providing a direct and efficient channel for fuzzing the Linux kernel's wireless stacks.

Key Findings

▶ Watch: Leveraging VirtIO devices for fuzzing (2:50)

The Verf fuzzer demonstrated remarkable success, uncovering a total of 31 new vulnerabilities across the Linux kernel's wireless stacks, leading to the assignment of 6 CVEs. The findings were split almost evenly, with 16 vulnerabilities in the Bluetooth stack and 15 in the Wi-Fi stack. This substantial number of discoveries underscores the previously unaddressed security gaps in these critical components.

The types of vulnerabilities found were diverse and severe, encompassing a range of memory corruption issues and logic flaws. These included heap overflows, use-after-free bugs, null pointer dereferences, slab out-of-bounds accesses, memory leaks, integer underflows, and infinite loops. Such vulnerabilities often lead to system instability, denial of service (DoS), or, more critically, provide pathways for remote code execution (RCE).

A particularly alarming aspect of the Wi-Fi vulnerabilities discovered is their remotely exploitable nature, requiring no user interaction. Specifically, these flaws were found in the processing of Wi-Fi Beacon frames. Beacon frames are continuously broadcast by access points to advertise their presence and network parameters. A device (like a phone or laptop) passively receives and processes these frames simply to identify available networks, meaning an attacker can trigger these vulnerabilities by merely broadcasting a malicious Beacon frame within range, without needing the victim to connect to a specific network or perform any action. The impact is further magnified by the fact that these Wi-Fi vulnerabilities also partially affect Android devices, leading to significant media coverage.

The longevity of some of these vulnerabilities also highlights the depth of Verf's findings. For instance, some Wi-Fi vulnerabilities affected Linux kernel versions as early as 5.1, while certain Bluetooth issues were present in versions as old as 2.6.28, indicating that these flaws had persisted for years, if not decades, undetected by previous testing efforts.

Beyond specific bug counts, Verf's effectiveness was formally evaluated by comparing its basic block coverage against Syzkaller, a well-known Linux kernel fuzzer. Over a 24-hour test period, Verf consistently achieved better basic block coverage in both Wi-Fi and Bluetooth subsystems. In the Bluetooth stack, Verf covered 162 functions, whereas Syzkaller only covered 96, with only 7 of Syzkaller's covered functions not also being covered by Verf. This quantitative data firmly establishes Verf's superior ability to explore the target code paths. The evaluation also confirmed the benefit of using authentic seed inputs: while a fuzzer starting with random inputs eventually reaches similar coverage, the use of real-world collected inputs provides a significant head start of several hours, accelerating the discovery process.

Technical Deep Dive

▶ Watch: Their innovative Universal VirtIO Device (3:50)

Verf's architecture is meticulously designed around its three core principles: depth, authenticity, and extensibility. The fuzzer operates by leveraging a custom Universal VirtIO Device integrated into the QEMU hypervisor, allowing it to interact with the guest Linux kernel's wireless drivers in a highly controlled and efficient manner.

The Universal VirtIO Device is a cornerstone of Verf. Instead of building a specific VirtIO device for each wireless protocol (e.g., Bluetooth, Wi-Fi) with its own complex state logic, the researchers developed a generic VirtIO device. This device, patched into QEMU, starts by reading a simple JSON configuration file. This file specifies the VirtIO ID (which device it should emulate, e.g., a network card, a Bluetooth controller), along with other standard VirtIO configuration information, features, and crucially, which VirtQueues are used for transmitting and receiving frames. When QEMU starts a virtual machine, this universal device initializes itself as the specified VirtIO device, performing the standard PCI negotiation and feature exchange with the guest. Critically, instead of implementing the full device logic, it simply sets up the VirtQueues and tunnels them to a Unix socket. This socket then becomes the direct communication channel for the fuzzer running outside the VM. This design allows the guest Linux kernel to believe it's interacting with a standard hardware device, while the fuzzer controls the raw input and output streams.

To address the authenticity goal, Verf incorporates a mechanism for collecting real-world inputs. Before active fuzzing begins, the Universal VirtIO Device is used in a proxy mode. A small proxy application running in the virtual machine connects on one side to the VirtIO device (which is now tunneling to the fuzzer's input collection component) and on the other side to a real hardware controller (e.g., a physical Bluetooth dongle). By using the Bluetooth controller from within the VM to pair with real-world devices, the proxy collects and saves all the actual frames generated during these interactions. These authentic seeds are then used to bootstrap the fuzzing process, providing a more relevant starting corpus than randomly generated data, which was shown to accelerate coverage acquisition significantly.

The fuzzer's operational flow involves the external fuzzer sending inputs through the Unix socket to the Universal VirtIO Device in QEMU. The VirtIO device then presents these inputs to the guest Linux kernel via the appropriate VirtQueue, where they are processed by the target wireless subsystem's driver.

For efficient coverage collection, Verf integrates with KCOV, Linux's kernel code coverage mechanism. Standard KCOV operations typically require system calls from user space to configure and collect coverage data. However, since Verf operates outside the kernel, interacting via VirtIO, this approach is not feasible. To overcome this, the researchers patched KCOV to write coverage information directly to shared memory accessible by both the guest kernel and the external fuzzer. Furthermore, to precisely delineate the scope of fuzzing, small KCOV annotations (simple function calls) are added around the entry points of the target code within the kernel (e.g., the network or Wi-Fi subsystem). These annotations instruct KCOV when to start and stop writing coverage data to shared memory. For example, the Bluetooth subsystem required only minor changes: two files modified, 12 insertions, and 2 deletions for these annotations. Verf collects two types of coverage: AFL-style map coverage and comparison tracking, the latter based on the "Red Queen" paper, which is crucial for overcoming "magic blocks" and other complex input validation logic that often hinders basic fuzzers.

Crash detection is achieved by continuously parsing the kernel log. Any problems, errors, or outputs from kernel sanitizers (like KASAN) are written to the kernel log, and Verf monitors this output to identify crashes or abnormal behavior.

Finally, for its core fuzzing capabilities (mutators and input schedulers), Verf leverages LibAFL, a fuzzer library that provides modular building blocks. This allowed the researchers to focus on the unique VirtIO integration and kernel instrumentation rather than reinventing standard fuzzing components.

Demo / Proof of Concept

▶ Watch: Fuzzer architecture: KCOV, shared memory, LibAFL (5:20)

While the presentation did not feature a live demonstration of an exploit being triggered, the talk thoroughly described the operational mechanics of the Verf fuzzer and presented concrete evidence of its effectiveness through the discovery of numerous severe vulnerabilities. The extensive list of 31 new vulnerabilities across Wi-Fi and Bluetooth stacks, including 5 CVEs specifically for Wi-Fi, serves as a powerful proof of concept for Verf's capabilities.

The finding of remotely exploitable Wi-Fi vulnerabilities, particularly those triggered by Beacon frames requiring no user interaction, inherently demonstrates the high impact of the fuzzer's output. The speakers highlighted that these vulnerabilities could lead to denial of service attacks and potentially remote code execution on affected Linux systems, including Android devices. The detailed table of findings, showing affected Linux kernel versions and bug types, further substantiates the severity and real-world applicability of the discovered flaws, acting as a testament to Verf's success in uncovering critical security weaknesses.

Defensive Implications

▶ Watch: Critical Wi-Fi vulnerabilities and CVEs found (7:00)

The findings from Verf have significant implications for system defenders, highlighting critical areas requiring immediate attention and long-term strategic changes in security posture.

Firstly, the discovery of numerous severe vulnerabilities, some of which persisted across many kernel versions (e.g., Linux 2.6.28 to 5.1), underscores the paramount importance of prompt and consistent patching. Organizations and individual users must prioritize updating their Linux kernels to the latest stable versions to mitigate known vulnerabilities. The long lifespan of these bugs suggests that wireless stacks have historically been an underserved area in terms of comprehensive security testing.

Secondly, the nature of the Wi-Fi vulnerabilities—remotely exploitable without user interaction via Beacon frames—is particularly concerning. This means that devices merely processing ambient wireless traffic are at risk. Defenders should be aware of this attack vector and understand that traditional user-centric security measures (e.g., "don't click suspicious links") are insufficient here. It emphasizes the need for robust input validation and memory safety within wireless drivers themselves, as these are the first line of defense against untrusted, over-the-air inputs.

Thirdly, Verf's success provides a strong argument for the integration of specialized, deep-kernel fuzzing into the development and testing pipelines for critical kernel subsystems, especially those dealing with external, untrusted input like wireless communication. Generic fuzzers, while valuable, may not achieve the necessary depth or authenticity to uncover subtle, protocol-specific flaws. This implies that developers of operating systems and device drivers should consider adopting or developing similar targeted fuzzing methodologies.

Furthermore, the technique of leveraging VirtIO devices for fuzzing presents a powerful paradigm. While Verf used VirtIO to attack the guest, the broader implication is that VirtIO itself, and other paravirtualization interfaces, represent an increasingly critical attack surface in virtualized environments. Defenders managing virtual machines should be aware that vulnerabilities in the VirtIO drivers within the guest or the VirtIO emulation in the hypervisor could be exploited.

Finally, the benefit of authentic, real-world inputs for fuzzing should be a key takeaway for security teams. Collecting and using actual network traffic or protocol interactions as initial seeds can significantly accelerate the bug discovery process and improve the relevance of the found vulnerabilities, leading to more impactful security improvements.

Key Takeaways

  • Novel VirtIO Fuzzing Approach: Verf introduces a groundbreaking methodology that leverages a custom Universal VirtIO Device within QEMU to deeply and authentically fuzz Linux kernel wireless stacks, proving highly effective where existing solutions fall short.
  • Significant Vulnerabilities Uncovered: The fuzzer discovered 31 new vulnerabilities (6 CVEs) across Linux's Wi-Fi and Bluetooth stacks, including severe memory corruption issues and logic flaws, many of which persisted for years across kernel versions.
  • Remote Exploitation Without User Interaction: Critical Wi-Fi vulnerabilities were found to be remotely exploitable via malicious Beacon frames, requiring no user interaction, posing a substantial threat to Linux systems, including Android devices.
  • Authentic Seeds Accelerate Discovery: Starting the fuzzing process with real-world collected inputs provides a significant "head start" and accelerates coverage acquisition, demonstrating the value of authenticity in fuzzing campaigns.
  • Enhanced Kernel Coverage: Verf achieved superior basic block coverage compared to Syzkaller in targeted wireless subsystems, exploring previously uncovered functions and highlighting the need for specialized fuzzing techniques.
  • Critical Need for Wireless Stack Security: The research underscores that wireless communication stacks are a high-risk attack surface, demanding continuous, deep-seated security testing and prompt patching to protect against pervasive and impactful threats.

About the Speaker(s)

Jan Sönke Huster is presented as the primary speaker and author of the paper. At the time of the research and presentation, he was a PhD student at the University of Gotan, having conducted this work during his tenure at the Secure Mobile Networking Lab at TU Darmstadt, Germany. His expertise lies in developing novel fuzzing techniques to uncover vulnerabilities in complex software systems, particularly within operating system kernels and wireless communication stacks.

Matthias Hollick is a co-author of the paper and is associated with the Secure Mobile Networking Lab at TU Darmstadt, Germany. His contributions align with the lab's focus on secure mobile networking, encompassing various aspects of wireless security and system resilience.

Jiska Classen is also a co-author and affiliated with the Secure Mobile Networking Lab at TU Darmstadt, Germany. Her work often involves security research in wireless technologies, including Bluetooth and Wi-Fi, contributing to the understanding and mitigation of vulnerabilities in these pervasive communication standards.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research introduces Verf, a highly innovative fuzzer leveraging a custom VirtIO device to penetrate and uncover significant vulnerabilities in Linux's wireless stacks. Its ability to simulate real hardware and use authentic network traffic as seeds led to the discovery of 31 severe, remotely exploitable flaws, including RCEs in Wi-Fi and Bluetooth, many affecting Android. This work sets a new bar for kernel fuzzing authenticity and depth.

Heather Calloway (CISO) — STRONG ACCEPT

This research uncovers critical, long-standing vulnerabilities in foundational wireless communication stacks, exposing devices to remote exploitation with no user interaction. It provides actionable insights for CISOs and security leaders on patching priorities, expanding threat models, and demanding more rigorous testing from vendors.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024