Skip to content
Preprint

One Is Not Enough: The Untold Story of Multiple Security Patches for One Vulnerability

Sep 2026 · 0 citations · 58 references
Computer Science

TL;DR

The results show that multi-SP vulnerabilities are both prevalent and systematically underreported, motivating stronger patch-completeness awareness, improved vulnerability database curation, and relation-aware security tooling.

Abstract

Security patches (SPs) are the main mechanism for fixing software vulnerabilities, yet a single vulnerability is not always resolved by a single patch: fixes may be completed incrementally, propagated across maintained branches, or replicated across related repositories. When patch records are incomplete, downstream users may observe only part of the required fix set and therefore apply only partial patching. However, comprehensive patch discovery remains difficult because the prevalence and causes of the multi-SP phenomenon are still poorly understood. In this paper, we present the first large-scale empirical study of multi-SP vulnerabilities. By merging four major vulnerability databases, we construct a dataset of 6,053 multi-SP CVEs with 16,260 SPs, showing that 20.6% of CVEs with patches involve multiple SPs and that merging databases increases recognized multi-SP CVE counts by 36-55% over any single source. We further analyze why a vulnerability is associated with multiple SPs and derive a two-level taxonomy with 6 categories and 16 sub-categories. Based on these findings, we develop SPectre, a taxonomy-driven prototype for comprehensive patch discovery. On 300 multi-SP CVEs, after manually verifying ground-truth SPs, SPectre improves multi-SP patch coverage over representative patch localization baselines, achieving 0.927 recall on same-repository cases and 0.873 recall on cross-repository cases after manual ground truth verification. On 100 recent CVEs recorded as single-patch by all public databases, SPectre further discovers 28 previously unreported SPs across 20 CVEs. Our results show that multi-SP vulnerabilities are both prevalent and systematically underreported, motivating stronger patch-completeness awareness, improved vulnerability database curation, and relation-aware security tooling.

View source

Similar papers

Preprint Sep 2026

COMPASS: Predicting the Relationship of Multiple Patches for Vulnerabilities with LLMs

Modern software heavily relies on code reuse, so upstream vulnerability fixes do not automatically propagate to downstream codebases. Downstream maintainers must manually adopt patches to eliminate known risks. In practice, a single vulnerability often corresponds to multiple patches, which greatly complicates downstre...

Yi Song, Dong-Chen Xie, Xiao-Yuan Xie et al. · 0 citations
Preprint Aug 2026

Benchmarking Automated Security Patch Backporting: How Far Are We?

This work presents Porting Benchmark, a curated dataset of 1,234 security patch backporting cases spanning cross-version, cross-branch, and cross-repository scenarios, paired with a common evaluation framework and identifies four root-cause categories (missing target API awareness, cross-version semantic mismatch, non-...

Jincheng Yang, Yulong Fu, Chengwei Liu et al. · 1 citation
Preprint Aug 2026

eBPF Security in the Wild: Structural Concentration, Failure Mechanisms, and Discovery Gaps

Extended Berkeley Packet Filter (eBPF) is a security-critical in-kernel execution framework, yet its vulnerability landscape remains fragmented across components, semantic gaps, and testing techniques. We present an empirical study of observed eBPF vulnerabilities. We construct a multi-source dataset from Linux kernel...

Bai-Hong Chen, Ming Hua, Wei-Feng Pan et al. · 0 citations
Review Open access Aug 2026

Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges

This research evaluates how these threats have metastasized and traces the origins of modern security vectors to determine if established defensive protocols remain effective against increasingly complex modern exploitation tactics, and reveals a definitive and strategic maturation in adversarial approach.

Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas et al. · 0 citations
#artificial intelligence Preprint Sep 2026

No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

This work proposes a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available, and introduces no-box vulnerability analysis as a new analysis paradigm and demonstrates its practical feasibility in realistic systems.

Ze-Hua Zhang, Jie Hu, Pratham Hegde et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.