SPIDER: Enabling Fast Patch Propagation In Related Software Repositories
Aravind Machiry, Nilo Redini, Eric Camellini, Christopher Kruegel, Giovanni Vigna
Abstract
Despite the effort of software maintainers, patches to open-source repositories are propagated from the main codebase to all the related projects (e.g., forks) with a significant delay. Previous work shows that this is true also for security patches, which represents a critical problem. Vulnerability databases, such as the CVE database, were born to speed-up the application of critical patches; however, patches associated with CVE entries (i.e., CVE patches) are still applied with a delay, and some security fixes lack the corresponding CVE entries. Because of this, project maintainers could miss security patches when upgrading software.In this paper, we are the first to define safe patches (sps). An sp is a patch that does not disrupt the intended functionality of the program (on valid inputs), meaning that it can be applied with no testing; we argue that most security fixes fall into this category. Furthermore, we show a technique to identify sps, and implement SPIDER 1, a tool based on such a technique that works by analyzing the source code of the original and patched versions of a file. We performed a large-scale evaluation on 341,767 patches from 32 large and popular source code repositories as well as on 809 CVE patches. Results show that SPIDER was able to identify 67,408 sps and that most of the CVE patches are sps. In addition, SPIDER identified 2,278 patches that fix vulnerabilities lacking a CVE; 229 of these are still unpatched in different vendor kernels, which can be considered as potential unfixed vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 75d226e9-4c19-40b3-9004-b7a6945407cfCited by top-tier papers19
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao et al.CCS 2021 · 43 citations
- PatchScope: Memory Object Centric Patch DiffingLei Zhao, Yuncong Zhu, Jiang Ming, Yichen Zhang et al.CCS 2020 · 21 citations
- Understanding the Practice of Security Patch Management across Multiple Branches in OSS ProjectsXin Tan, Yuan Zhang, Jiajun Cao, Kun Sun et al.WWW 2022 · 19 citations
- Responsibility in Context: On Applicability of Slicing in Semantic Regression AnalysisSahar Badihi, Khaled Ahmed, Yi Li, Julia RubinICSE 2023 · 2 citations
- SymRadar: PoC-Centered Bounded Verification for Vulnerability RepairSeungheon Han, YoungJae Kim, Yeseung Lee, Jooyong YiICSE 2026 · 1 citation
Builds on3
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Using Safety Properties to Generate Vulnerability PatchesZhen Huang, David Lie, Gang Tan, Trent JaegerS&P 2019 · 91 citations
Related papers
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao et al.ASE 2024 · 1 citation
- Tracking patches for open source software vulnerabilitiesCongying Xu, Bihuan Chen, Chenhao Lu, Kaifeng Huang et al.FSE 2022 · 34 citations
- Unveiling the Characteristics and Impact of Security Patch EvolutionZifan Xie, Ming Wen, Zichao Wei, Hai JinASE 2024 · 2 citations
- Repository-Level Graph Representation Learning for Enhanced Security Patch DetectionXin-Cheng Wen, Zirui Lin, Cuiyun Gao, Hongyu Zhang et al.ICSE 2025 · 1 citation
- Precise (Un)Affected Version Analysis for Web VulnerabilitiesYoukun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao et al.ASE 2022 · 7 citations
