VLDB 2026 Research / reviewers in the wild / expert
Yuhang Wu 0003
dblp:41/7732-3
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2025
0000-0002-0641-9107ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PATCHAGENT: A Practical Program Repair Agent Mimicking Human Expertise
Zheng Yu 0003, Yuhang Wu 0003, Jiahao Yu 0001, Meng Xu 0025, Dongliang Mu, Yan Chen 0004, Xinyu Xing 0001 |
USENIX Security Symposium | 3 |
| 2024 | Towards Unveiling Exploitation Potential With Multiple Error Behaviors for Kernel BugsabstractNowadays, fuzz testing has significantly expedited the vulnerability discovery of Linux kernel. Security analysts use the manifested error behaviors to infer the exploitability of one bug and thus prioritize the patch development. However, only using an error behavior in the report, security analysts might underestimate the exploitability of the kernel bug because it could manifest various error behaviors indicating different exploitation potentials. In this work, we conduct an empirical study on multiple error behaviors of kernel bugs to understand 1) the prevalence of multiple error behaviors and the possible impact of multiple error behaviors towards the exploitation potential; 2) the factors that manifest multiple error behaviors with different exploitation potential. We collectedall the fixed kernel bugsreported on Syzbot from September 2017 to January 2022, including 3,352 bug reports. We observed that multiple error behaviors manifested by kernel bugs are prevalent in the real world, and more error behaviors help unveil the exploitability of kernel bugs. Then we organized Linux kernel experts to analyze a sample of kernel bug dataset (484 bug reports, unique 162 bugs) and identified 6 key contributing factors to the mutiple error behaviors. Finally, based on the empirical findings, we propose an object-driven fuzzing technique to explore all possible error behaviors that a kernel bug might bring about. To evaluate the utility of our proposed technique, we implement our fuzzing toolGREBEand apply it to 60 real-world Linux kernel bugs. On average,GREBEcould manifest 2+ additional error behaviors for each of the kernel bugs. For 26 kernel bugs,GREBEdiscovers higher exploitation potential. We report to kernel vendors some of the bugs – the exploitability of which was wrongly assessed and the corresponding patch has not yet been carefully applied – resulting in their rapid patch adoption. Ziqin Liu, Zhenpeng Lin, Yueqi Chen 0001, Yuhang Wu 0003, Yalong Zou, Dongliang Mu, Xinyu Xing 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Mitigating Security Risks in Linux with KLAUS: A Method for Evaluating Patch Correctness
Yuhang Wu 0003, Zhenpeng Lin, Yueqi Chen 0001, Dang K. Le, Dongliang Mu, Xinyu Xing 0001 |
USENIX Security Symposium | 1 |
| 2022 | DirtyCred: Escalating Privilege in Linux KernelabstractThe kernel vulnerability DirtyPipe was reported to be present in nearly all versions of Linux since 5.8. Using this vulnerability, a bad actor could fulfill privilege escalation without triggering existing kernel protection and exploit mitigation, making this vulnerability particularly disconcerting. However, the success of DirtyPipe exploitation heavily relies on this vulnerability's capability (i.e., injecting data into the arbitrary file through Linux's pipes). Such an ability is rarely seen for other kernel vulnerabilities, making the defense relatively easy. As long as Linux users eliminate the vulnerability, the system could be relatively secure. Zhenpeng Lin, Yuhang Wu 0003, Xinyu Xing 0001 |
CCS | 2 |
| 2022 | An In-depth Analysis of Duplicated Linux Kernel Bug Reports
Dongliang Mu, Yuhang Wu 0003, Yueqi Chen 0001, Zhenpeng Lin, Chensheng Yu, Xinyu Xing 0001, Gang Wang 0011 |
NDSS | 2 |
| 2022 | GREBE: Unveiling Exploitation Potential for Linux Kernel BugsabstractNowadays, dynamic testing tools have significantly expedited the discovery of bugs in the Linux kernel. When unveiling kernel bugs, they automatically generate reports, specifying the errors the Linux encounters. The error in the report implies the possible exploitability of the corresponding kernel bug. As a result, many security analysts use the manifested error to infer a bug’s exploitability and thus prioritize their exploit development effort. However, using the error in the report, security researchers might underestimate a bug’s exploitability. The error exhibited in the report may depend upon how the bug is triggered. Through different paths or under different contexts, a bug may manifest various error behaviors implying very different exploitation potentials. This work proposes a new kernel fuzzing technique to explore all the possible error behaviors that a kernel bug might bring about. Unlike conventional kernel fuzzing techniques concentrating on kernel code coverage, our fuzzing technique is more directed towards the buggy code fragment. It introduces an object-driven kernel fuzzing technique to explore various contexts and paths to trigger the reported bug, making the bug manifest various error behaviors. With the newly demonstrated errors, security researchers could better infer a bug’s possible exploitability. To evaluate our proposed technique’s effectiveness, efficiency, and impact, we implement our fuzzing technique as a tool GREBE and apply it to 60 real-world Linux kernel bugs. On average, GREBE could manifest 2+ additional error behaviors for each of the kernel bugs. For 26 kernel bugs, GREBE discovers higher exploitation potential. We report to kernel vendors some of the bugs – the exploitability of which was wrongly assessed and the corresponding patch has not yet been carefully applied – resulting in their rapid patch adoption. Zhenpeng Lin, Yueqi Chen 0001, Yuhang Wu 0003, Dongliang Mu, Chensheng Yu, Xinyu Xing 0001 |
SP | 3 |