# UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windows

> A University of Texas at Dallas study (Qi, Li, Wang; ESORICS 2026) manually examined 1,646 multi-patch fix records among open-source CVEs in NVD (1999-2025) and found 31.7% take more than a day between the first and last commit, creating an N-day window across unpatched branches, release lines, or forks. Seven ML-based incomplete-fix detectors (CodeBERT, UniXcoder, LineVul, Devign, ReVeal) scored under 50% accuracy/F1, and clone detectors ReDebug and FIRE degraded sharply across branches (FIRE's true-positive rate fell from ~90% to ~52%), meaning defenders cannot rely on automated tooling to flag an incomplete patch.

- **Published:** 2026-07-26T00:00:00Z
- **Last reviewed:** 2026-07-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1704
- **ID:** TL-2026-1704
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2012-0038, CVE-2023-4226, CVE-2022-2522

## Description

Researchers Weiliang Qi, Youpeng Li, and Xinda Wang at the University of Texas at Dallas published "Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software" (arXiv:2607.13206, accepted ESORICS 2026), manually reviewing 1,646 open-source CVE records from NVD (1999-2025) whose fixes spanned more than one commit -- about 6.7% of all open-source CVEs with linked patches, averaging 2.55 patches per CVE.

The study builds a three-category, six-subcategory taxonomy for why fixes fragment: (1) the same defect exists in multiple code locations, branches, or downstream forks requiring distributed patches -- ImageMagick alone accounted for roughly one-third of its fixes this way due to parallel release-line maintenance; (2) ancillary, non-security commits (documentation edits, version bumps, temporary workarounds) get bundled with or precede the real fix, affecting 5.8% of cases; and (3) the initial patch was incomplete or defective and reintroduced or failed to close the flaw -- 641 of 1,646 records, the second-largest subcategory.

Critically, 31.7% of multi-patch fixes took more than 24 hours between the first and final corrective commit. During that window, a vulnerability disclosed or partially patched on one branch remains exploitable on sibling branches, release lines, or downstream forks that have not yet received the follow-up commit -- an N-day exposure that exists purely because of patch fragmentation, independent of any vendor delay in initial disclosure.

Three real CVEs illustrate each pattern. CVE-2012-0038 (Linux kernel, CWE-190, integer overflow in xfs_acl_from_disk): the first commit (093019cf1b18dd31b2c3b77acce4e000e2cbc9ce) added a bounds check but used a helper returning an unsigned int against a signed count variable, letting a negative count bypass the check; a second, corrective commit (fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba) landed roughly 18 days later, converting the variable to unsigned and closing the bypass -- an 18-day window during which the initial "fixed" kernel remained vulnerable to a local DoS/heap corruption via a malformed on-disk ACL. CVE-2023-4226 (Chamilo LMS, CWE-434, unrestricted file upload in /main/inc/ajax/work.ajax.php): STAR Labs SG researcher Ngo Wei Lin disclosed to the vendor on 2023-09-04 that an authenticated learner-role user could upload a PHP web shell plus a crafted .htaccess into the app cache directory to obtain RCE; Chamilo shipped a workaround-level commit before a complete closing fix followed roughly 16 days later, with the full release (v1.11.26) and public disclosure landing 2023-09-27 and 2023-11-28 respectively. CVE-2022-2522 (Vim, CWE-122, heap-based buffer overflow, published 2022-07-25): the study found the accepted fix retained an unrelated, non-security commit alongside the real change, and after a user flagged the residual defect, the vendor never issued a further correction -- the case sits permanently in the "incomplete/never corrected" bucket rather than resolving within days.

None of the three example CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-07-26; they are presented as illustrative, patched (or permanently unresolved) case studies of the fragmentation phenomenon rather than active in-the-wild campaigns. The operational risk is structural and forward-looking: any future multi-branch CVE has roughly a 1-in-3 chance of leaving a same-day-undetectable N-day gap that current commercial and open-source incomplete-fix detectors are not equipped to flag.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1204 User Execution
- T1505 Server Software Component
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1552 Unsecured Credentials
- T1518 Software Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1041 Exfiltration Over C2 Channel
- T1499 Endpoint Denial of Service

## Sources

- [Multi-patch vulnerability fixes can leave open source exposed](https://www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/)
- [Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software](https://arxiv.org/abs/2607.13206)
- [Multiple Patch Fixes Pose Security Risks to Open Source Projects](https://www.news4hackers.com/multiple-patch-fixes-pose-security-risks-to-open-source-projects)
- [NVD - CVE-2012-0038](https://nvd.nist.gov/vuln/detail/cve-2012-0038)
- [NVD - CVE-2023-4226](https://nvd.nist.gov/vuln/detail/CVE-2023-4226)
- [NVD - CVE-2022-2522](https://nvd.nist.gov/vuln/detail/CVE-2022-2522)
- [(CVE-2023-4226) Chamilo LMS Work Ajax File Upload Functionality Remote Code Execution](https://starlabs.sg/advisories/23/23-4226)
- [Linux kernel commit 093019cf1b18dd31b2c3b77acce4e000e2cbc9ce (initial xfs_acl_from_disk fix)](https://github.com/torvalds/linux/commit/093019cf1b18dd31b2c3b77acce4e000e2cbc9ce)
- [Linux kernel commit fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba (corrective follow-up fix)](https://github.com/torvalds/linux/commit/fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba)
- [Vim patch commit 5fa9f23a63651a8abdb074b4fc2ec9b1adc6b089](https://github.com/vim/vim/commit/5fa9f23a63651a8abdb074b4fc2ec9b1adc6b089)
- [Vim patch commit b9e717367c395490149495cf375911b5d9de889e](https://github.com/vim/vim/commit/b9e717367c395490149495cf375911b5d9de889e)
- [Huntr bounty report for Vim heap-based buffer overflow (CVE-2022-2522)](https://huntr.dev/bounties/3a2d83af-9542-4d93-8784-98b115135a22)
- [Red Hat Bugzilla #773280 (xfs_acl_from_disk integer overflow)](https://bugzilla.redhat.com/show_bug.cgi?id=773280)
- [kqueue.org: CVE-2012-0038 XFS ACL count integer overflow](https://kqueue.org/blog/2012/01/10/cve-2012-0038-xfs-acl-count-integer-overflow/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1704
