Automated Detection of Configuration-Specific Security Vulnerabilities via Patch Analysis
Felipe de Sant'Anna Paixão, Joanna C. S. Santos, Paulo Anselmo da Mota Silveira Neto, Daniel Sadoc Menasché, Gustavo Bittencourt Figueiredo, Eduardo Santana de Almeida
Abstract
We study how security patches in highly configurable C/C++ systems map onto the space of compile-time variants. We formalize the Vulnerability Impact Condition (VIC)—a Boolean predicate over configuration options that denotes all variants that contained the original flaw—and introduce PatchLens, a purely static technique that recovers VICs by aligning AST-level patch hunks with source-level presence conditions and resolving file inclusion via lightweight build system analysis. Evaluating PatchLens on 1,192 Linux kernel, 289 FFmpeg, and 100 PHP patches, we compute precise, human-readable VICs without the need to compile any system variant. The resulting predicates are compact (avg. 1.84 variables for Linux, 3.23 for FFmpeg, 1.04 for PHP) and show that only a small fraction of vulnerabilities are system-wide, which carry higher CVSS scores; meanwhile, CVE texts almost never encode the required options (≈1% average recall), motivating automated enrichment of CVE descriptions with VICs. PatchLens and the accompanying dataset enable immediate applications in CI (variant-aware triage and test selection), targeted sampling and fuzzing, and feature risk scoring, offering a scalable, explainable path to vulnerability assessment in highly configurable software.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 34e0cc72-4999-4c0f-b1de-0a4c0360cdb8Builds on3
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- V-SZZ: Automatic Identification of Version Ranges Affected by CVE VulnerabilitiesLingfeng Bao, Xin Xia, Ahmed E. Hassan, Xiaohu YangICSE 2022 · 45 citations
- Maximizing Patch Coverage for Testing of Highly-Configurable Software without Exploding Build TimesNecip Fazil Yildiran, Jeho Oh, Julia Lawall, Paul GazzilloFSE 2024 · 7 citations
Related papers
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao et al.CCS 2021 · 43 citations
- SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept ExploitsWei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang et al.CCS 2017 · 148 citations
- Towards More Accurate Static Analysis for Taint-Style Bug Detection in Linux KernelHaonan Li, Hang Zhang, Kexin Pei, Zhiyun QianASE 2025 · 5 citations
- OS-Aware Vulnerability Prioritization via Differential Severity AnalysisQiushi Wu, Yue Xiao, Xiaojing Liao, Kangjie LuUSENIX Security 2022
- Inferring 1-Minimal Trigger Configurations for Assessing Linux Kernel CVE TriggerabilityTongjie Wei, Peng Zhang, Zhiwen Hu, Xupu Hu et al.ISSTA 2026
