Loading…
June 26 - 27 | Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Linux Security Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (MDT | UTC-6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."
Friday June 27, 2025 1:40pm - 2:25pm MDT
The popularity of fuzzing has led to its tight integration
into the software development process as a routine part
of the build and test, i.e., continuous fuzzing. This has
resulted in a substantial increase in the reporting of bugs
in open-source software, including the Linux kernel. To
keep up with the volume of bugs, it is crucial to automatically analyze the bugs to assist developers and maintain-
ers. Bug bisection, i.e., locating the commit that introduced a vulnerability, is one such analysis that can reveal
the range of affected software versions and help bug prioritization and patching. However, existing automated
solutions fall short in a number of ways: most of them either (1) directly run the same PoC on older software ver-
sions without adapting to changes in bug-triggering conditions and are prone to broken dynamic environments
or (2) require patches that may not be available when
the bug is discovered. In this work, we take a different approach to looking for evidence of fuzzer-exposed
vulnerabilities by looking for the underlying bug logic.
In this way, we can perform bug bisection much more
precisely and accurately.
Speakers
avatar for zheng zhang

zheng zhang

Research Scientist, Meta
Zheng Zhang is a research scientist at Meta. He earned a Ph.D. in Computer Science from UCR. His research interests focus on vulnerability detection, with a particular emphasis on vulnerabilities in popular open-source systems like Linux, including zero-day vulnerabilities and N-day... Read More →
Friday June 27, 2025 1:40pm - 2:25pm MDT
Room BBB 3G+3H

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link