Posts by Collection

portfolio

FuzzUEr: UEFI Firmware Fuzzer

A fuzzing framework for UEFI firmware interfaces on EDK-2, with firmware-adapted sanitizers, discovering 20 zero-day vulnerabilities. Published at NDSS 2025.

Checked C for UEFI Firmware

Compiler-based vulnerability prevention for firmware: extending 3C to bring automated spatial memory safety to EDK II. Published at ISSTA 2025.

Kernel CVE Analysis

Collaborative research on Linux/Android kernel vulnerability analysis, exploit adaptation, and crash reproduction.

publications

FuzzUEr: Enabling Fuzzing of UEFI Interfaces on EDK-2

Published in Network and Distributed System Security Symposium (NDSS 2025), 2025

FuzzUEr is a novel fuzzing framework for testing UEFI firmware interfaces on EDK-2, which discovered 20 zero-day security vulnerabilities in the latest version of EDK-II.

Recommended citation: Connor Glosner, Aravind Machiry. "FuzzUEr: Enabling Fuzzing of UEFI Interfaces on EDK-2." NDSS 2025. https://cglosner.github.io/files/FuzzUEr__Enabling_Fuzzing_of_UEFI_Interfaces__on__EDK2.pdf

Adding Spatial Memory Safety to EDK II through Checked C (Experience Paper)

Published in ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2025), 2025

This paper presents our experience adding spatial memory safety guarantees to the UEFI firmware reference implementation (EDK II) using Checked C, a backward-compatible extension of C with bounds-checked pointer types.

Recommended citation: Sourag Cherupattamoolayil, Arunkumar Bhattar, Connor Glosner, Aravind Machiry. "Adding Spatial Memory Safety to EDK II through Checked C (Experience Paper)." ISSTA 2025. https://cglosner.github.io/files/Converting_EDK_II_to_Checked_C_with_3C.pdf

talks

FuzzUEr: Enabling Fuzzing of UEFI Interfaces on EDK-2

Published:

Presented our work on FuzzUEr, a novel fuzzing framework for testing UEFI firmware interfaces on EDK-2. This work discovered 20 zero-day security vulnerabilities in the latest version of EDK-II.

teaching