Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability Lifespans
Simge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon, Tudor Dumitras
Abstract
The emergence of immutable infrastructures such as container ecosystems has transformed how software is built, deployed, and maintained. In particular, patches that were traditionally delivered through in-place updates are now applied through image rebuilds and propagated through hierarchies of dependent images. Despite these substantial structural changes in patch delivery, the security impacts, such as the lifecycle of vulnerabilities and patching responsibilities in the software supply chain, remain understudied. Examining maintainer and user interactions across official Docker repositories, we find that maintainers often rely on automated patching of inherited vulnerabilities rather than intervening manually, while unclear maintenance timelines and responsibility boundaries impede remediation when automation halts. Building on these insights, we present the first longitudinal study of vulnerability lifespans in the Docker ecosystem, spanning six years. We analyze over 9,000 CVEs across 137 applications (from 756,313 images), and find that 78 % of inherited vulnerabilities remain unresolved 30 days after disclosure. The predominant cause of prolonged exposure is the breakdown of automated patch propagation due to upstream end-of-life (EOL) events, leaving 11 %-and up to in deeper dependency layers-of inherited vulnerabilities unpatched even when fixes exist. Based on these findings, we provide actionable recommendations to reduce the window of exposure to vulnerability exploits and release a tool to improve transparency. More broadly, our work provides empirical insights into the fragility of automated patch propagation in software supply chains, emphasizing the need for clear maintenance practices and accountability across dependency hierarchies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f0a09c3a-28cc-4afc-8a2a-b2dee985d48eBuilds on9
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- Asking for a Friend: Evaluating Response Biases in Security User StudiesElissa M. Redmiles, Ziyun Zhu, Sean Kross, Dhruv Kuchhal et al.CCS 2018 · 65 citations
- From Patching Delays to Infection Symptoms: Using Risk Profiles for an Early Discovery of Vulnerabilities Exploited in the WildChaowei Xiao, Armin Sarabi, Yang Liu, Bo Li et al.USENIX Security 2018 · 31 citations
- A different cup of TI? The added value of commercial threat intelligenceXander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr et al.USENIX Security 2020
Related papers
- Dr. Docker: A Large-Scale Security Measurement of Docker Image EcosystemHequan Shi, Lingyun Ying, Libo Chen, Haixin Duan et al.WWW 2025 · 1 citation
- Unveiling the Characteristics and Impact of Security Patch EvolutionZifan Xie, Ming Wen, Zichao Wei, Hai JinASE 2024 · 2 citations
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang et al.ICSE 2024 · 10 citations
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu et al.ASE 2023 · 25 citations
