This paper proposes RustGo, the new Rust-directed greybox fuzzer that effectively and fairly focuses on code regions potentially containing memory bugs and automatically identifies potential memory bug targets and accurately prunes the paths irrelevant to each target by leveraging Rust-specific static analysis.
Abstract
Rust is a popular systems programming language that provides strong memory safety and introduces low-performance overhead. While Rust guarantees memory safety through strict security policies, such as ownership, memory bugs can still occur in unsafe-related Rust codes where these policies are not fully enforced. Although such unsafe Rust code accounts for only a small portion of the entire code (e.g., 10%), existing approaches fuzz the entire code-including safe Rust, whose memory safety is already enforced by the Rust compiler-resulting in inefficient use of fuzzing resources. In this paper, we propose RustGo, the new Rust-directed greybox fuzzer that effectively and fairly focuses on code regions potentially containing memory bugs. For this, RustGo automatically identifies potential memory bug targets and accurately prunes the paths irrelevant to each target by leveraging Rust-specific static analysis. For each identified target, RustGo includes a new fuzzing approach that maintains an independent state and applies dynamic pruning to maximize balanced and focused fuzzing. We evaluate RustGo on various real-world Rust applications. On average, RustGo prunes 78.49% of irrelevant paths, reaches targets x 2.09 to x 5.08 faster than existing fuzzers, and identifies 13 unknown bugs (six assigned RUSTSEC IDs and one assigned CVE ID).
UnsafeChecker is presented, a compiler-integrated static analysis framework for detecting potential soundness violations in Rust safe abstractions, and outperforms several state-of-the-art tools, detecting 32 CVEs and covering 36 bugs with 51.6% alert-level precision.
Xi-Zhe Yin, Yao Zhang, Yang Feng et al.· 0 citations
How to extend RefinedRust with several of the high-level abstractions that Rust provides, including traits, closures, and iterators, and in a manner such that they can be used in conjunction with unsafe code.
Lennard Gäher, Vincent Lafeychine, Sascha Kehrli et al.· Proceedings of the ACM on Pr...· 0 citations
An empirical study of 30 issues that report potential soundness bugs in rustc, collected from the GitHub issue tracker between January 1, 2022 and September 1, 2025, indicates that certain soundness bugs, typically triggered by implied bounds or trait objects, compromise memory safety.
Yusung Sim, Sukyoung Ryu, Jaemin Hong· Proceedings of the ACM on So...· 0 citations
An alternate agentic approach that gives an LLM freedom and guardrails is presented that gives an LLM freedom and guardrails in the Rust programming language, a promising replacement for C.
An alternative agentic approach that gives an LLM freedom and guardrails, and a publicly available implementation named ACTOR that outperforms all previous tools to automatically translate C to Rust.
Benedikt Schesch, Michael D. Ernst· IEEE Security & Privacy· 0 citations
SNIPTEST is an execution-based warning triage framework that generates and fuzzes compiled code slices centered around static-analysis warnings that employs a layer-by-layer slicing strategy, incrementally expanding context around the target location to validate potential vulnerabilities with increasing precision.
Aniruddhan Murali, Noble Saji Mathews, Mahmoud Alfadel et al.· IEEE Transactions on Softwar...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.