Listed as affected ≠ vulnerable
An affected range in a vulnerability database may include releases that already contain a fix. Choosing the wrong version makes subsequent builds and tests fruitless.
A PoC is only half the story. Starting from patches and kernel source, KernJC identifies truly affected versions, uncovers hidden configuration requirements, and automatically builds virtual environments for reproducing kernel vulnerabilities.
KERNEL JIAOCHANG / KERNEL TRAINING GROUND — RAID 2024
Evaluation samples reproduced
Requires non-default configurations
With incorrect version claims
Reproduction needs an environment where the vulnerability exists and is reachable from user space. A plausible version number and a vulnerable function in the source are only the starting point.
An affected range in a vulnerability database may include releases that already contain a fix. Choosing the wrong version makes subsequent builds and tests fruitless.
Conditional compilation and Kconfig relationships determine which features are present. The interface a PoC needs may depend on another configuration option.
Merge the configurations, compile the kernel, prepare a root filesystem, and boot a virtual machine. KernJC connects these steps into one workflow.
NVD CLAIM / VERSION RANGE RECORDED IN THE PAPER
KCONFIG / LOCAL GRAPH OF KEY REQUIREMENTS
← Scroll to explore the graph · Select a node to learn more →
This view shows a subset of direct configurations and one key hidden configuration. The full set includes more candidates. Colors indicate discovery progress, not kernel enablement; “Source / path analysis” means direct analysis is complete.
PROVISIONING / FROM SOURCE TO RUNTIME
DEMO INPUT: v5.11.14 + configurations discovered by KernJC
Build a profile from vulnerability information and patches, then connect version verification, configuration discovery, and environment generation. KernJC turns reproduction requirements into evidence that can be analyzed.
I / PATCH-BASED VERSION IDENTIFICATION
Map database claims to actual releases and scan down from the range’s upper bound. Use patch content and source context to detect existing fixes, skipping those releases until a candidate without the fix is found.
This step checks whether the fix is present. Successful reproduction still needs suitable configurations and a working PoC.
II / GRAPH-BASED CONFIG IDENTIFICATION
Extract direct configurations from descriptions, build paths, and conditional compilation. Model Kconfig’s depend, opaque_depend, select, and imply relationships as a directed graph to discover reachable and reverse-linked options.
The paper’s evaluation uses one-hop exploration for HSC / HDC; virtual menus do not count as hops. The output is a candidate configuration set, not necessarily a minimal set.
The paper evaluates 66 real kernel vulnerabilities from security research using existing PoCs. Each square is one sample; select it to inspect its reproduction requirements.
Sources: paper §5.2, Table 2, and Appendix B.
Results reflect the paper’s evaluation set and experimental setup.
66 samples · 32 need non-default configurations · 4 have version claim errors
CVE-2021-22555
Requires non-default configurations · Incorrect NVD version claim · Reproduced in a KernJC environment
Analysis of a larger dataset finds incorrect version claims for 128 CVEs, spanning 3,042 falsely reported version records. This analysis covers a different scope from the 66 PoC evaluation samples above.
READ §5.427th International Symposium on Research in Attacks, Intrusions and Defenses · RAID 2024 · pp. 384–402
@inproceedings{ruan2024kernjc,
title={KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities},
author={Ruan, Bonan and Liu, Jiahao and Zhang, Chuqi and Liang, Zhenkai},
booktitle={Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses},
pages={384--402},
year={2024},
doi={10.1145/3678890.3678891}
}