Threat reportThreat IntelligenceTL-2026-1704

UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windows

mediumACTIVE

UT Dallas Study (TL-2026-1704), also tracked as UT Dallas Multi-Patch Study, is a medium-severity tracked intrusion set, first published 2026-07-26. It has no confirmed attribution, affects Linux kernel community Linux kernel (XFS), references 3 CVEs (CVE-2012-0038, CVE-2023-4226, CVE-2022-2522), maps to 16 MITRE ATT&CK techniques (T1005, T1041, T1068), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
3Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1704

Threat ID
TL-2026-1704
Also known as
UT Dallas Multi-Patch Study, Why Not Fix It Once and for All?
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Motivation
UNKNOWN
Target sectors
technology, softwaredevelopment, education, government administration, criticalinfrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
28

Malware and tooling in UT Dallas Study

Malware and tooling: CodeBERT, Devign, FIRE, LineVul, ReDebug, ReVeal, UniXcoder

How UT Dallas Study works

A University of Texas at Dallas study (Qi, Li, Wang; ESORICS 2026) manually examined 1,646 multi-patch fix records among open-source CVEs in NVD (1999-2025) and found 31.7% take more than a day between the first and last commit, creating an N-day window across unpatched branches, release lines, or forks. Seven ML-based incomplete-fix detectors (CodeBERT, UniXcoder, LineVul, Devign, ReVeal) scored under 50% accuracy/F1, and clone detectors ReDebug and FIRE degraded sharply across branches (FIRE's true-positive rate fell from ~90% to ~52%), meaning defenders cannot rely on automated tooling to flag an incomplete patch.

Researchers Weiliang Qi, Youpeng Li, and Xinda Wang at the University of Texas at Dallas published "Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software" (arXiv:2607.13206, accepted ESORICS 2026), manually reviewing 1,646 open-source CVE records from NVD (1999-2025) whose fixes spanned more than one commit -- about 6.7% of all open-source CVEs with linked patches, averaging 2.55 patches per CVE.

The study builds a three-category, six-subcategory taxonomy for why fixes fragment: (1) the same defect exists in multiple code locations, branches, or downstream forks requiring distributed patches -- ImageMagick alone accounted for roughly one-third of its fixes this way due to parallel release-line maintenance; (2) ancillary, non-security commits (documentation edits, version bumps, temporary workarounds) get bundled with or precede the real fix, affecting 5.8% of cases; and (3) the initial patch was incomplete or defective and reintroduced or failed to close the flaw -- 641 of 1,646 records, the second-largest subcategory.

Critically, 31.7% of multi-patch fixes took more than 24 hours between the first and final corrective commit. During that window, a vulnerability disclosed or partially patched on one branch remains exploitable on sibling branches, release lines, or downstream forks that have not yet received the follow-up commit -- an N-day exposure that exists purely because of patch fragmentation, independent of any vendor delay in initial disclosure.

Three real CVEs illustrate each pattern. CVE-2012-0038 (Linux kernel, CWE-190, integer overflow in xfs_acl_from_disk): the first commit (093019cf1b18dd31b2c3b77acce4e000e2cbc9ce) added a bounds check but used a helper returning an unsigned int against a signed count variable, letting a negative count bypass the check; a second, corrective commit (fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba) landed roughly 18 days later, converting the variable to unsigned and closing the bypass -- an 18-day window during which the initial "fixed" kernel remained vulnerable to a local DoS/heap corruption via a malformed on-disk ACL. CVE-2023-4226 (Chamilo LMS, CWE-434, unrestricted file upload in /main/inc/ajax/work.ajax.php): STAR Labs SG researcher Ngo Wei Lin disclosed to the vendor on 2023-09-04 that an authenticated learner-role user could upload a PHP web shell plus a crafted .htaccess into the app cache directory to obtain RCE; Chamilo shipped a workaround-level commit before a complete closing fix followed roughly 16 days later, with the full release (v1.11.26) and public disclosure landing 2023-09-27 and 2023-11-28 respectively. CVE-2022-2522 (Vim, CWE-122, heap-based buffer overflow, published 2022-07-25): the study found the accepted fix retained an unrelated, non-security commit alongside the real change, and after a user flagged the residual defect, the vendor never issued a further correction -- the case sits permanently in the "incomplete/never corrected" bucket rather than resolving within days.

None of the three example CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-07-26; they are presented as illustrative, patched (or permanently unresolved) case studies of the fragmentation phenomenon rather than active in-the-wild campaigns. The operational risk is structural and forward-looking: any future multi-branch CVE has roughly a 1-in-3 chance of leaving a same-day-undetectable N-day gap that current commercial and open-source incomplete-fix detectors are not equipped to flag.

MITRE ATT&CK techniques used in TL-2026-1704

Collection

T1005 Data from Local System

Exfiltration

T1041 Exfiltration Over C2 Channel

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution; T1204 User Execution

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1499 Endpoint Denial of Service

Persistence

T1505 Server Software Component

Discovery

T1518 Software Discovery

Credential Access

T1552 Unsecured Credentials

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in UT Dallas Study

  • Linux kernel community — Linux kernel (XFS)
    Vulnerable versions: before 3.1.9
    Fixed in: 3.1.9 and later (commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba)
  • Chamilo Association — Chamilo LMS
    Vulnerable versions: up to 1.11.24
    Fixed in: 1.11.26 and later
  • Vim — vim/vim
    Vulnerable versions: before 9.0.0061
    Fixed in: 9.0.0061 and later
  • ImageMagick Studio LLC — ImageMagick
    Vulnerable versions: study finding is aggregate, not tied to a single CVE/version: ~30% of ImageMagick security fixes required multiple commits across parallel release lines
    Fixed in: varies per release line; not enumerated by the study

Remediation for UT Dallas Study

Patches

  • Linux kernel >= 3.1.9 (CVE-2012-0038)
  • Chamilo LMS >= 1.11.26 (CVE-2023-4226)
  • Vim >= 9.0.0061 (CVE-2022-2522)

Immediate actions

  • Treat the first published commit/patch for any multi-branch or multi-fork open-source CVE as provisional -- confirm whether NVD/vendor references list more than one corrective commit before marking the CVE closed
  • For CVE-2012-0038-class Linux kernel deployments, confirm kernel >= 3.1.9 (or backport of commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba, not just 093019cf1b18dd31b2c3b77acce4e000e2cbc9ce)
  • For Chamilo LMS, confirm version >= 1.11.26 (CVE-2023-4226 fully closed); versions <= 1.11.24 with only a partial workaround remain exploitable via /main/inc/ajax/work.ajax.php
  • For Vim, confirm version >= 9.0.0061 for CVE-2022-2522; note the study found the shipped fix still carries an unrelated commit, so re-verify against upstream if replicating this analysis

Workarounds

  • Restrict learner-role upload paths and disable .htaccess override in Chamilo's app/cache directory as a compensating control if unable to patch immediately
  • Disable untrusted ACL-bearing filesystem mounts on unpatched Linux kernels vulnerable to CVE-2012-0038

Longer-term hardening

  • Do not rely solely on CodeBERT/UniXcoder/LineVul/Devign/ReVeal-class ML incomplete-fix classifiers or ReDebug/FIRE-class clone detectors as a sole gate for patch-completeness verification -- all scored below 50% accuracy/F1 or degraded sharply (FIRE: ~90% to ~52% TPR) across branches in the study
  • Build patch-verification workflow steps that explicitly check for follow-up commits referencing the original CVE/commit hash across all maintained branches and downstream forks before closing a vulnerability-management ticket
  • Track average patch latency for multi-commit CVEs in your dependency tree; prioritize re-scanning branches/release lines that historically lag on follow-up commits (e.g., projects like ImageMagick with heavy parallel release-line maintenance)

CVEs associated with UT Dallas Study

CVE-2012-0038, CVE-2023-4226, CVE-2022-2522

Weaknesses (CWE) in UT Dallas Study

CWE-190, CWE-434, CWE-122

Timeline of UT Dallas Study

  • CVE-2012-0038 discussed on the oss-security mailing list; initial Linux kernel commit 093019cf1b18dd31b2c3b77acce4e000e2cbc9ce adds a bounds check to xfs_acl_from_disk but uses a helper returning an unsigned int against a signed count, leaving the check bypassable.
  • Corrective follow-up commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba lands roughly 18 days after the first, converting the ACL count variable to unsigned and closing the integer-overflow bypass in xfs_acl_from_disk.
  • CVE-2012-0038 formally published in the National Vulnerability Database.
  • CVE-2022-2522 (Vim heap-based buffer overflow, CWE-122) published; the UT Dallas study found the accepted fix retained an unrelated, non-security commit and the flaw was never further corrected after a user flagged it to the vendor.
  • STAR Labs SG researcher Ngo Wei Lin discloses the Chamilo LMS work.ajax.php unrestricted file upload (later CVE-2023-4226) to the vendor.
  • Chamilo LMS v1.11.26 released with the complete closing fix; the UT Dallas study identifies this as the second corrective commit, landing roughly 16 days after an initial workaround-only patch.
  • CVE-2023-4226 publicly disclosed and published in NVD and GitHub Security Advisories.
  • Qi, Li, and Wang submit "Why Not Fix It Once and for All?" (arXiv:2607.13206) to arXiv, accepted at ESORICS 2026, documenting the 1,646-record multi-patch CVE study.
  • Help Net Security publishes coverage of the UT Dallas multi-patch study, surfacing the N-day exposure-window finding and detection-tooling gap to SOC and patch-management audiences.

Sources cited for UT Dallas Study

Detection coverage for TL-2026-1704

As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1704 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats