[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-148438-105":59,"doc-detail-148438-en":134},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":127,"head_meta":129,"extra_data":131,"updated_unix":133},105,"en","undo-workarounds-for-kernel-bugs","Undo Workarounds for Kernel Bugs","","OS kernels contain bugs that undermine security, reliability, and usability. Kernel fuzzers can discover such issues, yet patching commonly takes many weeks or months, leaving a prolonged vulnerability window. The work introduces bowknots, kernel workarounds that preserve system functionality after a triggering syscall, avoid noticeable performance overhead, and remain lightweight. It also proposes Hecaton, a static analysis tool that automatically generates bowknots with minimal analyst support, improving fuzzing efficiency.",{"@graph":69,"@context":126},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/undo-workarounds-for-kernel-bugs/148438/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/undo-workarounds-for-kernel-bugs/148438.png","ImageObject",300,407,{"name":92,"@type":93},"Asher","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-10-02","2026-08-26",true,{"@type":102,"interactionType":103,"userInteractionCount":52},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118,122],{"name":109,"@type":110,"acceptedAnswer":111},"Why do kernel bugs remain a serious concern even when fuzzers exist?","Question",{"text":112,"@type":113},"Kernel fuzzers can find bugs, but patching is slow and often requires waiting months while the system stays exposed in the vulnerability window.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"What are bowknots and what problem do they solve?",{"text":117,"@type":113},"Bowknots are workarounds that keep kernel functionality working even when a bug-triggering syscall occurs, by undoing the syscall’s side effects to neutralize the bug impact.",{"name":119,"@type":110,"acceptedAnswer":120},"How does the bowknot approach avoid performance overhead?",{"text":121,"@type":113},"It stays mostly inactive until the bug is actually triggered, so it does not add noticeable overhead during normal operation.",{"name":123,"@type":110,"acceptedAnswer":124},"How does Hecaton help in deploying bowknots?",{"text":125,"@type":113},"Hecaton uses static analysis to generate bowknots automatically and inserts them into the kernel, requiring only minimal help from an analyst in the remaining cases.","https://schema.org",{"og:url":83,"og:type":128,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":130,"canonical":83},"index,follow",{"doc_id":132,"site_id":62},148438,1787779810,{"code":4,"msg":5,"data":135},{"doc_id":132,"user_id":136,"nickname":92,"user_avatar":137,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":138,"file_id":139,"file_url":140,"file_type":141,"file_size":142,"view_count":52,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":143,"language":144,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":145,"faqs":146,"seo_title":147,"seo_description":67,"update_tm":133,"read_time":148},687197207639,"https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd","Undo Workarounds for Kernel Bugs  \nSeyed Mohammadjavad Seyed Talebi?, Zhihao Yao? Ardalan Amiri Sani?, Zhiyun Qian†, Daniel Austin‡? UC Irvine,†UC Riverside,‡Atlassian􀀃  \nAbstract  \nOS kernels are full of bugs resulting in security, reliability, and usability issues. Several kernel fuzzers have recently been developed to ﬁnd these bugs and have proven to be effective. Yet, bugs take several months to be patched once they are discovered. In this window of vulnerability, bugs continue to pose concerns. We present workarounds for kernel bugs, called bowknots, which maintain the functionality of the system even when bugs are triggered, are applicable to many kernel bugs, do not cause noticeable performance overhead, and have a small kernel footprint. The key idea behind bowknots is to undo the side effects of the in-ﬂight syscall that triggersa bug, effectively neutralizing the syscall. We also present a static analysis tool, called Hecaton, that generates bowknots automatically and inserts them into the kernel. Through extensive evaluations on the kernel of Android devices as well as x86 upstream kernels, we demonstrate that bowknots are effective in mitigating kernel bugs and vulnerabilities. We also show that Hecaton is capable of generating the right bowknots fully automatically in majority of cases, and requires minimal help from the analyst for the rest. Finally, we demonstrate the beneﬁts of bowknots in improving the efﬁciency of kernel fuzzing by eliminating repetitive reboots.  \n1 Introduction  \nCommodity OS kernels are monolithic, large, and hence full of bugs. Bugs in the kernel cause important problems. First, they risk the system's security as some bugs might be exploitable vulnerabilities. The kernel is a highly privileged layer in the system software stack and hence is attractive to attackers. Indeed, OS kernels are hot targets for security attacks these days. For example, according to Google, an increasing number of attacks on mobile devices are targeting the kernel (i.e., 44% of attacks in 2016 vs. 9% and 4% of them in 2015 and 2014, respectively) [9] . Second, they impact the  \n􀀃 This research started while Mr. Austin was with Google, as part of the Android Security team.  \nreliability and usability of the system. Even a simple crash bug, e.g., a null pointer dereference, results in a system hang or reboot, causing usability issues for the users. Even worse, bugs can corrupt the state of the software and hardware and lead to unexpected behavior. Finally, as we will show, kernel bugs can even pose practical challenges for kernel fuzzing by inducing repetitive reboots and wasting the fuzzing time.  \nThe common practice today is to ﬁnd these bugs and patch them. There has been a lot of progress recently to automate the ﬁrst step (i.e., ﬁnding bugs) . More speciﬁcally, several kernel fuzzers have been recently developed such as Syzkaller [13], kAFL [36], Digtool [32], and MoonShine [31] . Indeed, these fuzzers have been successfully used to ﬁnd bugs in the kernel [10, 12, 37]. However, the second step (i.e., patching bugs) remains a highly manual and lengthy process. In practice, this requires reporting the bug to the developers of the code, e.g., the vendor in charge of a device driver, and waiting for a patch. Unfortunately, this wait can take months for the bug to sit in a queue, be evaluated by developers, and get a patch developed, tested, and merged into the kernel. Our study of bugs found by Syzkaller [12] shows that bugs have taken on average 66 days to be patched. Moreover, at the time of the study (November 2019), there were several open bugs that were waiting for a patch for an average of 233 days. While waiting for a patch, the kernel remains vulnerable.  \nIn this paper, we introduce workarounds for kernel bugs before they are correctly patched. We refer to such a workaround as a Bug undO Workaround for KerNel sOlidiTy (bowknot) . A bowknot has ﬁve important properties. First, it is fast to generate. Unli","cbCaivmvY3w3HmVA","https://ap.wps.com/l/cbCaivmvY3w3HmVA","pdf",1125505,18,"English","# Abstract\n# Introduction\n## Kernel bugs and their impact\n## Limits of fuzzing and patching timelines\n## Bowknots concept and properties\n## Undoing syscall side effects","[{\"question\":\"Why do kernel bugs remain a serious concern even when fuzzers exist?\",\"answer\":\"Kernel fuzzers can find bugs, but patching is slow and often requires waiting months while the system stays exposed in the vulnerability window.\"},{\"question\":\"What are bowknots and what problem do they solve?\",\"answer\":\"Bowknots are workarounds that keep kernel functionality working even when a bug-triggering syscall occurs, by undoing the syscall’s side effects to neutralize the bug impact.\"},{\"question\":\"How does the bowknot approach avoid performance overhead?\",\"answer\":\"It stays mostly inactive until the bug is actually triggered, so it does not add noticeable overhead during normal operation.\"},{\"question\":\"How does Hecaton help in deploying bowknots?\",\"answer\":\"Hecaton uses static analysis to generate bowknots automatically and inserts them into the kernel, requiring only minimal help from an analyst in the remaining cases.\"}]","Undo Workarounds for Kernel Bugs | PDF",45]