{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:15:05Z","timestamp":1781284505218,"version":"3.54.1"},"reference-count":54,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2024,9,27]],"date-time":"2024-09-27T00:00:00Z","timestamp":1727395200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R & D Program of China","doi-asserted-by":"crossref","award":["2022YFE0113200"],"award-info":[{"award-number":["2022YFE0113200"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["U21A20464"],"award-info":[{"award-number":["U21A20464"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Hong Kong Polytechnic University","award":["1-ZVG0, H-ZGGG"],"award-info":[{"award-number":["1-ZVG0, H-ZGGG"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2024,9,30]]},"abstract":"<jats:p>The Linux kernel is popular and well-maintained. Over the past decade, around 860 thousand commits were merged with hundreds of vulnerabilities (i.e., 223 on average) disclosed every year, taking the total lines of code to 35.1 million in 2022. Many algorithms have been proposed to detect the vulnerabilities, but few studied how they were induced. To fill this gap, we conduct the first empirical study on the Kernel Vulnerability Inducing Commits (KVIC), the commits that induced vulnerabilities in the Linux kernel. We utilized six different methods on identifying the Kernel Vulnerability Fixing Commits (KVFCs), the commits that fix vulnerabilities in the Linux kernel, and proposed the other four different methods for identifying KVICs by using the identified KVFCs as a bridge. In total, we constructed the first dataset of KVICs with 1,240 KVICs for 1,335 CVEs. We conducted a thorough analysis on the characteristics, purposes, and involved human factors of the KVICs and obtained many interesting findings and insights. For example, KVICs usually have limited reviewers and can still be induced by experienced authors or maintainers. Based on these insights, we proposed several suggestions to the Linux community to help mitigate the induction of KVICs.<\/jats:p>","DOI":"10.1145\/3672452","type":"journal-article","created":{"date-parts":[[2024,6,14]],"date-time":"2024-06-14T15:58:30Z","timestamp":1718380710000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Understanding Vulnerability Inducing Commits of the Linux Kernel"],"prefix":"10.1145","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2196-6894","authenticated-orcid":false,"given":"Muhui","family":"Jiang","sequence":"first","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2065-9211","authenticated-orcid":false,"given":"Jinan","family":"Jiang","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4102-601X","authenticated-orcid":false,"given":"Tao","family":"Wu","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7439-2823","authenticated-orcid":false,"given":"Zuchao","family":"Ma","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9082-3208","authenticated-orcid":false,"given":"Xiapu","family":"Luo","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7610-4736","authenticated-orcid":false,"given":"Yajin","family":"Zhou","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,9,27]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"2024. Android Security Bulletin. Retrieved from https:\/\/source.android.com\/security\/bulletin"},{"key":"e_1_3_1_3_2","unstructured":"The MITRE Corp. 2015. CVE-2015-8970. Retrieved from https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-8970"},{"key":"e_1_3_1_4_2","doi-asserted-by":"crossref","unstructured":"Canonical Ltd. 2019. CVE-2019-15220. Retrieved from https:\/\/ubuntu.com\/security\/CVE-2019-15220","DOI":"10.5465\/AMBPP.2019.15220abstract"},{"key":"e_1_3_1_5_2","unstructured":"The MITRE Corp. 2024. CVE List. Retrieved from https:\/\/cve.mitre.org\/"},{"key":"e_1_3_1_6_2","unstructured":"National Institute of Standards and Technology. 2024. CVSS Version 3.0. Retrieved from https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v3-calculator"},{"key":"e_1_3_1_7_2","unstructured":"The MITRE Corp. 2024. CWE. Retrieved from https:\/\/cwe.mitre.org\/"},{"key":"e_1_3_1_8_2","unstructured":"GitHub Inc. 2024. Linux Kernel CVE Project. Retrieved from https:\/\/github.com\/nluedtke\/linux_kernel_cves"},{"key":"e_1_3_1_9_2","unstructured":"The Kernel Development Community. 2024. Linux kernel Patch Guide. Retrieved from https:\/\/www.kernel.org\/doc\/html\/latest\/process\/submitting-patches.html"},{"key":"e_1_3_1_10_2","unstructured":"National Institute of Standards and Technology. 2024. National Vulnerability Database. Retrieved from https:\/\/nvd.nist.gov\/"},{"key":"e_1_3_1_11_2","unstructured":"Canonical Ltd. 2024. Ubuntu CVEs. Retrieved from https:\/\/ubuntu.com\/security\/cve"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/2642937.2642990"},{"key":"e_1_3_1_13_2","first-page":"359","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security \u201922)","author":"Alexopoulos Nikolaos","year":"2022","unstructured":"Nikolaos Alexopoulos, Manuel Brack, Jan Philipp Wagner, Tim Grube, and Max M\u00fchlh\u00e4user. 2022. How long do vulnerabilities live in the code? A large-scale empirical measurement study on FOSS vulnerability lifetimes. In Proceedings of the 31st USENIX Security Symposium (USENIX Security \u201922). 359\u2013376."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510113"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3340482.3342742"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/2597073.2597108"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2016.2616306"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2010.5463279"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1002\/smr.1619"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/32.815326"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380397"},{"key":"e_1_3_1_22_2","first-page":"124","volume-title":"Proceedings of the World Congress on Engineering and Computer Science","author":"Gayatri N.","year":"2010","unstructured":"N. Gayatri, S. Nickolas, A. V. Reddy, S. Reddy, and A. V. Nickolas. 2010. Feature selection using decision tree induction in class level metrics dataset for software defect predictions. In Proceedings of the World Congress on Engineering and Computer Science. 124\u2013129."},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/2961111.2962602"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070510"},{"key":"e_1_3_1_25_2","first-page":"99","volume-title":"Proceedings of the 2008 International Working Conference on Mining Software Repositories","author":"Hindle Abram","year":"2008","unstructured":"Abram Hindle, Daniel M. German, and Ric Holt. 2008. What do large commits tell us? A taxonomical study of large commits. In Proceedings of the 2008 International Working Conference on Mining Software Repositories. 99\u2013108."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568320"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/METRIC.2002.1011339"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2006.23"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2008.90"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2017.42"},{"key":"e_1_3_1_32_2","unstructured":"Xingyu Li Zheng Zhang Zhiyun Qian Trent Jaeger and Chengyu Song. An investigation of patch porting practices of the Linux kernel ecosystem. arXiv:2402.05212 [cs.SE]."},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2402.05212"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/1368088.1368114"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062514"},{"key":"e_1_3_1_36_2","volume-title":"Proceedings of 2021 Annual Network and Distributed System Security Symposium","author":"Navid Emamdoost","year":"2021","unstructured":"Emamdoost Navid, Wu Qiushi, Lu Kangjie, and McCamant Stephen. 2021. Detecting kernel memory leaks in specialized modules with ownership reasoning. In Proceedings of 2021 Annual Network and Distributed System Security Symposium."},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473122"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-012-9218-8"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3387904.3389267"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09781-y"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2803183"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464821"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/1082983.1083147"},{"key":"e_1_3_1_44_2","first-page":"492","volume-title":"Proceedings of the 2nd international conference on Software Engineering","author":"Burton Swanson E.","year":"1976","unstructured":"E. Burton Swanson. 1976. The dimensions of maintenance. In Proceedings of the 2nd international conference on Software Engineering. 492\u2013497."},{"key":"e_1_3_1_45_2","first-page":"2471","volume-title":"Proceedings of the 30th  \\(\\{\\mathrm{USENIX}\\}\\)  Security Symposium","author":"Tan Xin","year":"2021","unstructured":"Xin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu, and Min Yang. 2021. Detecting kernel refcount bugs with two-dimensional consistency checking. In Proceedings of the 30th \\(\\{\\mathrm{USENIX}\\}\\) Security Symposium. 2471\u20132488."},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337269"},{"key":"e_1_3_1_47_2","first-page":"13","volume-title":"Proceedings of the 12th International Conference on Quality Software","author":"Wang Jun","year":"2012","unstructured":"Jun Wang, Beijun Shen, and Yuting Chen. 2012. Compressed C4. 5 models for software defect prediction. In Proceedings of the 12th International Conference on Quality Software. IEEE, 13\u201316."},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387464"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884804"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338962"},{"key":"e_1_3_1_51_2","first-page":"3041","volume-title":"Proceedings of the 30th USENIX Security Symposium","author":"Woo Seunghoon","year":"2021","unstructured":"Seunghoon Woo, Dongwook Lee, Sunghan Park, Heejo Lee, and Sven Dietrich. 2021. V0Finder: Discovering the correct origin of publicly reported software vulnerabilities. In Proceedings of the 30th USENIX Security Symposium. 3041\u20133058."},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPP.2012.30"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025121"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3213846.3213866"},{"issue":"1","key":"e_1_3_1_55_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3468854","article-title":"SPI: Automated identification of security patches via commits","volume":"31","author":"Zhou Yaqin","year":"2021","unstructured":"Yaqin Zhou, Jing K. Siow, Chenyu Wang, Shangqing Liu, and Yang Liu. 2021. SPI: Automated identification of security patches via commits. ACM Transactions on Software Engineering and Methodology (TOSEM) 31, 1 (2021), 1\u201327.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3672452","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3672452","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:58:01Z","timestamp":1750294681000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3672452"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,27]]},"references-count":54,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2024,9,30]]}},"alternative-id":["10.1145\/3672452"],"URL":"https:\/\/doi.org\/10.1145\/3672452","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9,27]]},"assertion":[{"value":"2023-07-13","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-04-23","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}