BONAN RUAN / RESEARCH EXHIBIT
LINUX KERNEL · VULNERABILITY REPRODUCTION

KernJC

Reproduce vulnerabilities
in the right kernel

A PoC is only half the story. Starting from patches and kernel source, KernJC identifies truly affected versions, uncovers hidden configuration requirements, and automatically builds virtual environments for reproducing kernel vulnerabilities.

KERNEL JIAOCHANG / KERNEL TRAINING GROUND   —   RAID 2024

From versions and configurations to a reproducible environmentAn original layered diagram: verified kernel source, a configuration dependency graph, and a root filesystem combine into a QEMU virtual machine. The orange node represents a hidden configuration. ROOT FILESYSTEM HIDDEN CONFIG KCONFIG DEPENDENCIES VERIFIED KERNEL SOURCE 01 / VERSION02 / CONFIG03 / ROOTFS QEMU / REPRO ENVvulnerability reachable ENVIRONMENT, RECONSTRUCTED
FIG. 01   THE MISSING HALFCODE-DRAWN / SVG + CSS
Best Practical Paper Award27th RAID · 2024
66/ 66

Evaluation samples reproduced

48.5%

Requires non-default configurations

128CVEs

With incorrect version claims

You have a PoC
Why won’t it reproduce?

Reproduction needs an environment where the vulnerability exists and is reachable from user space. A plausible version number and a vulnerable function in the source are only the starting point.

A / VERSION GAP

Listed as affected ≠ vulnerable

An affected range in a vulnerability database may include releases that already contain a fix. Choosing the wrong version makes subsequent builds and tests fruitless.

B / CONFIG GAP

Compiled in ≠ reachable

Conditional compilation and Kconfig relationships determine which features are present. The interface a PoC needs may depend on another configuration option.

C / ENVIRONMENT GAP

Source selected, environment next

Merge the configurations, compile the kernel, prepare a root filesystem, and boot a virtual machine. KernJC connects these steps into one workflow.

Build the missing environment

CVE-2021-22555 / NETFILTER / PAPER CASE STUDY
kernjc / environment workbenchInteractive demo · No kernel build runs here

NVD CLAIM / VERSION RANGE RECORDED IN THE PAPER

< v5.12Claimed range includes patched releases
← Earlier releasesCheck down from the upper bound ←
net/netfilter/x_tables.c
// fixing patch / source context
xt_compat_target_from_user(...) The fixing patch’s changes are already present in the source
SELECTED: v5.11.22
v5.11.22 is patched and cannot reproduce this vulnerability.
01 / Check whether the version already contains the fixCASE SOURCE / §2.2 ↗

Two kinds of evidence
One reproduction workflow

Build a profile from vulnerability information and patches, then connect version verification, configuration discovery, and environment generation. KernJC turns reproduction requirements into evidence that can be analyzed.

I / PATCH-BASED VERSION IDENTIFICATION

Calibrate version boundaries with patches

Map database claims to actual releases and scan down from the range’s upper bound. Use patch content and source context to detect existing fixes, skipping those releases until a candidate without the fix is found.

3.91 sAverage version identification time in the paper
Excludes kernel compilation and environment startup

This step checks whether the fix is present. Successful reproduction still needs suitable configurations and a working PoC.

II / GRAPH-BASED CONFIG IDENTIFICATION

From explicit clues to hidden relationships

Extract direct configurations from descriptions, build paths, and conditional compilation. Model Kconfig’s depend, opaque_depend, select, and imply relationships as a directed graph to discover reachable and reverse-linked options.

DDCFrom descriptions
DPCFrom source paths
DCCFrom source code

The paper’s evaluation uses one-hop exploration for HSC / HDC; virtual menus do not count as hops. The output is a candidate configuration set, not necessarily a minimal set.

The right environment
Successful reproduction

The paper evaluates 66 real kernel vulnerabilities from security research using existing PoCs. Each square is one sample; select it to inspect its reproduction requirements.

66 / 66Reproduced successfully
in KernJC environments

Sources: paper §5.2, Table 2, and Appendix B.
Results reflect the paper’s evaluation set and experimental setup.

Reproducible with default configurationsRequires non-default configurationsIncorrect version claim

66 samples · 32 need non-default configurations · 4 have version claim errors

CVE-2021-22555

Requires non-default configurations · Incorrect NVD version claim · Reproduced in a KernJC environment

128 CVEs / BROADER VERSION ANALYSIS

Analysis of a larger dataset finds incorrect version claims for 128 CVEs, spanning 3,042 falsely reported version records. This analysis covers a different scope from the 66 PoC evaluation samples above.

READ §5.4

KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities

27th International Symposium on Research in Attacks, Intrusions and Defenses · RAID 2024 · pp. 384–402

Bonan Ruan · Jiahao Liu · Chuqi Zhang · Zhenkai Liang
National University of Singapore