Crash2PoC: Agentic Root Cause Analysis and Reproducer Synthesis for Linux Kernel Bugs
Abstract
Large language model (LLM)-driven agents have shown considerable promise in software engineering. However, their reliability remains limited in tasks that require jointly interpreting noisy execution reports and searching through large codebases. Reproducing Linux kernel vulnerabilities exemplifies this challenge: an agent must extract critical evidence from crash logs, locate the relevant code in the correct kernel revision, derive a well-grounded root-cause explanation, and generate an executable proof-of-concept (PoC) reproducer. We present Crash2PoC, a tool-augmented agentic framework that incorporates execution feedback to improve the reliability of kernel vulnerability reproduction. Crash2PoC decomposes the workflow into three stages: agent-driven crash localization, static-analysis-guided evidence enrichment, and agent-reasoning-supported root-cause PoC generation. We evaluate Crash2PoC on real-world Linux kernel vulnerabilities detected by sanitizers. Our results show that integrating static analysis, dynamic execution feedback, and agent-based reasoning improves the success rate of generating validated vulnerability reproducers.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.