What is it about?

Software vulnerabilities do not always exist independently. Attackers can potentially combine multiple bugs into a single exploit chain to achieve more powerful attacks. This work presents an automated agentic pipeline that determines whether multiple vulnerabilities can be triggered by the same input. The approach uses LLM-generated predicates and constraint-based harnesses together with symbolic execution and SMT solving to analyze buggy code and search for shared triggering inputs. The methodology is evaluated on real-world vulnerabilities in widely used open-source projects, including tcpdump, libxml2, and nDPI.

Featured Image

Why is it important?

This research is important because traditional vulnerability analysis typically examines bugs in isolation, while real attackers may exploit combinations of vulnerabilities. Automatically identifying whether bugs can be triggered together helps uncover potential exploit chains, distinguish feasible bug combinations from impossible ones, and prioritize the most critical vulnerabilities for patching.

Read the Original

This page is a summary of: Bug Composition: Triggering Multiple Bugs with Agentic Driver Generation, October 2026, ACM (Association for Computing Machinery),
DOI: 10.1145/3843282.3844434.
You can read the full text:

Read

Contributors

The following have contributed to this page