Threat reportThreat IntelligenceTL-2026-1704
UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windows
UT Dallas Study (TL-2026-1704), also tracked as UT Dallas Multi-Patch Study, is a medium-severity tracked intrusion set, first published 2026-07-26. It has no confirmed attribution, affects Linux kernel community Linux kernel (XFS), references 3 CVEs (CVE-2012-0038, CVE-2023-4226, CVE-2022-2522), maps to 16 MITRE ATT&CK techniques (T1005, T1041, T1068), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-1704
- Threat ID
- TL-2026-1704
- Also known as
- UT Dallas Multi-Patch Study, Why Not Fix It Once and for All?
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Motivation
- UNKNOWN
- Target sectors
- technology, softwaredevelopment, education, government administration, criticalinfrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in UT Dallas Study
Malware and tooling: CodeBERT, Devign, FIRE, LineVul, ReDebug, ReVeal, UniXcoder
How UT Dallas Study works
A University of Texas at Dallas study (Qi, Li, Wang; ESORICS 2026) manually examined 1,646 multi-patch fix records among open-source CVEs in NVD (1999-2025) and found 31.7% take more than a day between the first and last commit, creating an N-day window across unpatched branches, release lines, or forks. Seven ML-based incomplete-fix detectors (CodeBERT, UniXcoder, LineVul, Devign, ReVeal) scored under 50% accuracy/F1, and clone detectors ReDebug and FIRE degraded sharply across branches (FIRE's true-positive rate fell from ~90% to ~52%), meaning defenders cannot rely on automated tooling to flag an incomplete patch.
Researchers Weiliang Qi, Youpeng Li, and Xinda Wang at the University of Texas at Dallas published "Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software" (arXiv:2607.13206, accepted ESORICS 2026), manually reviewing 1,646 open-source CVE records from NVD (1999-2025) whose fixes spanned more than one commit -- about 6.7% of all open-source CVEs with linked patches, averaging 2.55 patches per CVE.
The study builds a three-category, six-subcategory taxonomy for why fixes fragment: (1) the same defect exists in multiple code locations, branches, or downstream forks requiring distributed patches -- ImageMagick alone accounted for roughly one-third of its fixes this way due to parallel release-line maintenance; (2) ancillary, non-security commits (documentation edits, version bumps, temporary workarounds) get bundled with or precede the real fix, affecting 5.8% of cases; and (3) the initial patch was incomplete or defective and reintroduced or failed to close the flaw -- 641 of 1,646 records, the second-largest subcategory.
Critically, 31.7% of multi-patch fixes took more than 24 hours between the first and final corrective commit. During that window, a vulnerability disclosed or partially patched on one branch remains exploitable on sibling branches, release lines, or downstream forks that have not yet received the follow-up commit -- an N-day exposure that exists purely because of patch fragmentation, independent of any vendor delay in initial disclosure.
Three real CVEs illustrate each pattern. CVE-2012-0038 (Linux kernel, CWE-190, integer overflow in xfs_acl_from_disk): the first commit (093019cf1b18dd31b2c3b77acce4e000e2cbc9ce) added a bounds check but used a helper returning an unsigned int against a signed count variable, letting a negative count bypass the check; a second, corrective commit (fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba) landed roughly 18 days later, converting the variable to unsigned and closing the bypass -- an 18-day window during which the initial "fixed" kernel remained vulnerable to a local DoS/heap corruption via a malformed on-disk ACL. CVE-2023-4226 (Chamilo LMS, CWE-434, unrestricted file upload in /main/inc/ajax/work.ajax.php): STAR Labs SG researcher Ngo Wei Lin disclosed to the vendor on 2023-09-04 that an authenticated learner-role user could upload a PHP web shell plus a crafted .htaccess into the app cache directory to obtain RCE; Chamilo shipped a workaround-level commit before a complete closing fix followed roughly 16 days later, with the full release (v1.11.26) and public disclosure landing 2023-09-27 and 2023-11-28 respectively. CVE-2022-2522 (Vim, CWE-122, heap-based buffer overflow, published 2022-07-25): the study found the accepted fix retained an unrelated, non-security commit alongside the real change, and after a user flagged the residual defect, the vendor never issued a further correction -- the case sits permanently in the "incomplete/never corrected" bucket rather than resolving within days.
None of the three example CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-07-26; they are presented as illustrative, patched (or permanently unresolved) case studies of the fragmentation phenomenon rather than active in-the-wild campaigns. The operational risk is structural and forward-looking: any future multi-branch CVE has roughly a 1-in-3 chance of leaving a same-day-undetectable N-day gap that current commercial and open-source incomplete-fix detectors are not equipped to flag.
MITRE ATT&CK techniques used in TL-2026-1704
Collection
Exfiltration
T1041 Exfiltration Over C2 Channel
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution; T1204 User Execution
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Impact
T1499 Endpoint Denial of Service
Persistence
T1505 Server Software Component
Discovery
Credential Access
Resource Development
Reconnaissance
Affected products and versions in UT Dallas Study
- Linux kernel community — Linux kernel (XFS)
Vulnerable versions: before 3.1.9
Fixed in: 3.1.9 and later (commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba) - Chamilo Association — Chamilo LMS
Vulnerable versions: up to 1.11.24
Fixed in: 1.11.26 and later - Vim — vim/vim
Vulnerable versions: before 9.0.0061
Fixed in: 9.0.0061 and later - ImageMagick Studio LLC — ImageMagick
Vulnerable versions: study finding is aggregate, not tied to a single CVE/version: ~30% of ImageMagick security fixes required multiple commits across parallel release lines
Fixed in: varies per release line; not enumerated by the study
Remediation for UT Dallas Study
Patches
- Linux kernel >= 3.1.9 (CVE-2012-0038)
- Chamilo LMS >= 1.11.26 (CVE-2023-4226)
- Vim >= 9.0.0061 (CVE-2022-2522)
Immediate actions
- Treat the first published commit/patch for any multi-branch or multi-fork open-source CVE as provisional -- confirm whether NVD/vendor references list more than one corrective commit before marking the CVE closed
- For CVE-2012-0038-class Linux kernel deployments, confirm kernel >= 3.1.9 (or backport of commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba, not just 093019cf1b18dd31b2c3b77acce4e000e2cbc9ce)
- For Chamilo LMS, confirm version >= 1.11.26 (CVE-2023-4226 fully closed); versions <= 1.11.24 with only a partial workaround remain exploitable via /main/inc/ajax/work.ajax.php
- For Vim, confirm version >= 9.0.0061 for CVE-2022-2522; note the study found the shipped fix still carries an unrelated commit, so re-verify against upstream if replicating this analysis
Workarounds
- Restrict learner-role upload paths and disable .htaccess override in Chamilo's app/cache directory as a compensating control if unable to patch immediately
- Disable untrusted ACL-bearing filesystem mounts on unpatched Linux kernels vulnerable to CVE-2012-0038
Longer-term hardening
- Do not rely solely on CodeBERT/UniXcoder/LineVul/Devign/ReVeal-class ML incomplete-fix classifiers or ReDebug/FIRE-class clone detectors as a sole gate for patch-completeness verification -- all scored below 50% accuracy/F1 or degraded sharply (FIRE: ~90% to ~52% TPR) across branches in the study
- Build patch-verification workflow steps that explicitly check for follow-up commits referencing the original CVE/commit hash across all maintained branches and downstream forks before closing a vulnerability-management ticket
- Track average patch latency for multi-commit CVEs in your dependency tree; prioritize re-scanning branches/release lines that historically lag on follow-up commits (e.g., projects like ImageMagick with heavy parallel release-line maintenance)
CVEs associated with UT Dallas Study
CVE-2012-0038, CVE-2023-4226, CVE-2022-2522
Weaknesses (CWE) in UT Dallas Study
Timeline of UT Dallas Study
- CVE-2012-0038 discussed on the oss-security mailing list; initial Linux kernel commit 093019cf1b18dd31b2c3b77acce4e000e2cbc9ce adds a bounds check to xfs_acl_from_disk but uses a helper returning an unsigned int against a signed count, leaving the check bypassable.
- Corrective follow-up commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba lands roughly 18 days after the first, converting the ACL count variable to unsigned and closing the integer-overflow bypass in xfs_acl_from_disk.
- CVE-2012-0038 formally published in the National Vulnerability Database.
- CVE-2022-2522 (Vim heap-based buffer overflow, CWE-122) published; the UT Dallas study found the accepted fix retained an unrelated, non-security commit and the flaw was never further corrected after a user flagged it to the vendor.
- STAR Labs SG researcher Ngo Wei Lin discloses the Chamilo LMS work.ajax.php unrestricted file upload (later CVE-2023-4226) to the vendor.
- Chamilo LMS v1.11.26 released with the complete closing fix; the UT Dallas study identifies this as the second corrective commit, landing roughly 16 days after an initial workaround-only patch.
- CVE-2023-4226 publicly disclosed and published in NVD and GitHub Security Advisories.
- Qi, Li, and Wang submit "Why Not Fix It Once and for All?" (arXiv:2607.13206) to arXiv, accepted at ESORICS 2026, documenting the 1,646-record multi-patch CVE study.
- Help Net Security publishes coverage of the UT Dallas multi-patch study, surfacing the N-day exposure-window finding and detection-tooling gap to SOC and patch-management audiences.
Sources cited for UT Dallas Study
- Multi-patch vulnerability fixes can leave open source exposed
- Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software
- Multiple Patch Fixes Pose Security Risks to Open Source Projects
- NVD - CVE-2012-0038
- NVD - CVE-2023-4226
- NVD - CVE-2022-2522
- (CVE-2023-4226) Chamilo LMS Work Ajax File Upload Functionality Remote Code Execution
- Linux kernel commit 093019cf1b18dd31b2c3b77acce4e000e2cbc9ce (initial xfs_acl_from_disk fix)
- Linux kernel commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba (corrective follow-up fix)
- Vim patch commit 5fa9f23a63651a8abdb074b4fc2ec9b1adc6b089
- Vim patch commit b9e717367c395490149495cf375911b5d9de889e
- Huntr bounty report for Vim heap-based buffer overflow (CVE-2022-2522)
- Red Hat Bugzilla #773280 (xfs_acl_from_disk integer overflow)
- kqueue.org: CVE-2012-0038 XFS ACL count integer overflow
Detection coverage for TL-2026-1704
As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1704 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.