← Back to feed
Vendors & MarketEmerging1 sourceSep 8, 2026 · 07:00via Google Project Zero

Testing race conditions with memory access tracing and stack-based delay injection

Brief

Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases:

  • Confirming bug candidates that have been discovered manually or through static analysis.
  • Regression tests: After fixing a race condition bug, there is often no good way to write a regression test that reliably triggers the bug as part of a test suite.
  • Automatic bug discovery, such as fuzzing: It is hard for a fuzzer to exercise all interesting interleavings of concurrent operations, or reach code paths that are only exercised when operations are racing.

I mostly discover bugs by manually reading code. When I think I’ve found a bug, I normally write a test case to either prove or disprove that the bug exists. For race condition bugs, it can be hard to achieve either outcome.

Read more on Google Project Zero