Article may be outdated

This article is 69 days old. Some details may have changed since publication.

Help Net Security·4 min read·hard

patch vulnerability fixes can leave open source exposed

M
Mirko Zorz
patch vulnerability fixes can leave open source exposed
✦AI Summary

Researchers found that multi-patch vulnerability fixes in open-source software often leave systems exposed during the interval between initial and final patches. The study highlights that incomplete fixes or the need to port patches across multiple branches create significant security risks.

Why it matters

This identifies a critical flaw in standard cybersecurity patching workflows that could be exploited by attackers.

✦Dive DeeperCreate a free account to unlock

Multi-patch vulnerability fixes can leave open source exposed Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the flaw in place.

Researchers at the University of Texas at Dallas went through 1,646 open source CVEs that carry more than one patch in the National Vulnerability Database, drawn from records filed between 1999 and 2025. Those cases are a small share of the whole, close to one in fifteen of the open source CVEs in the database that carry a linked patch. The operational weight sits in the interval between the first patch and the last one, a window in which the software stays open.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in