{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:46:12Z","timestamp":1782848772787,"version":"3.54.5"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Unpatching, the process of reverting security patches to reintroduce historical vulnerabilities into newer software versions, is valuable for creating realistic benchmarks to evaluate security analysis tools. However, this process is challenging due to code evolution, leading to context conflicts, compilation errors, or untriggerable issues. In fact, 61.25% of Linux kernel security patches we examined cannot be trivially reverted to recent versions. To address this, we propose pPatch, an automated framework designed to systematically unpatch security vulnerabilities and generate vulnerability benchmark. pPatch overcomes the limitations of naive reversion by employing a novel approach that progressively consults conflicting commits to identify and integrate necessary code changes, aiming for minimal modifications to preserve program semantics while successfully re-exposing the original vulnerability and minimizing unintended side effects. Then pPatch unpatches 614 historic kernel vulnerabilities from Linux kernel v6.6 and v6.12, resulting in 371 and 353 successfully unpatched vulnerabilities with manual analysis.<\/jats:p>","DOI":"10.1145\/3808201","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"4415-4436","source":"Crossref","is-referenced-by-count":0,"title":["pPatch: Automated Vulnerability Unpatching"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0000-7691-6160","authenticated-orcid":false,"given":"Tianyi","family":"Jing","sequence":"first","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0009-2227-4559","authenticated-orcid":false,"given":"Pengyu","family":"Ding","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0001-6364-4837","authenticated-orcid":false,"given":"Meng","family":"Xu","sequence":"additional","affiliation":[{"name":"University of Waterloo, Waterloo, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0004-8487-4836","authenticated-orcid":false,"given":"Yinhao","family":"Hu","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"},{"name":"Zhongguancun Laboratory, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0000-1134-8115","authenticated-orcid":false,"given":"Zheng","family":"Yu","sequence":"additional","affiliation":[{"name":"Northwestern University, Evanston, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-8042-8928","authenticated-orcid":false,"given":"Dongliang","family":"Mu","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_2_1_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security '20)","author":"Blazytko Tim","year":"2020","unstructured":"Tim Blazytko, Moritz Schl\u00f6gel, Cornelius Aschermann, Ali Abbasi, Joel Frank, Simon W\u00f6rner, and Thorsten Holz. 2020. AURORA: Statistical Crash Analysis for Automated Root Cause Explanation. In Proceedings of the 29th USENIX Security Symposium (USENIX Security '20)."},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510230"},{"key":"e_1_2_2_4_1","volume-title":"Proceedings of the 34st USENIX Security Symposium (USENIX Security 25)","author":"B\u00f6lcskei Matej","year":"2025","unstructured":"Matej B\u00f6lcskei, Flavien Solt, Katharina Ceesay-Seitz, and Kaveh Razavi. 2025. Encarsia: Evaluating cpu fuzzers via automatic bug injection. In Proceedings of the 34st USENIX Security Symposium (USENIX Security 25)."},{"key":"e_1_2_2_5_1","unstructured":"Dan Carpenter. [n. d.]."},{"key":"e_1_2_2_6_1","unstructured":"Smatch. https:\/\/2.zoppoz.workers.dev:443\/https\/smatch.sourceforge.net\/."},{"key":"e_1_2_2_7_1","unstructured":"Kees Cook. 2024. Per-call-site slab caches for heap-spraying protection. https:\/\/2.zoppoz.workers.dev:443\/https\/lwn.net\/Articles\/986174\/."},{"key":"e_1_2_2_8_1","unstructured":"Linux Kernel Documentation. [n. d.]."},{"key":"e_1_2_2_9_1","unstructured":"Linux Kernel Testing. https:\/\/2.zoppoz.workers.dev:443\/https\/docs.kernel.org\/dev-tools\/testing-overview.html."},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.15"},{"key":"e_1_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639148"},{"key":"e_1_2_2_12_1","unstructured":"Fullway Wang. 2025. QlRules: Linux Rules Directory. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/fullwaywang\/QlRules\/tree\/main\/linux."},{"key":"e_1_2_2_13_1","first-page":"4535","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"G\u00f6rz Philipp","year":"2023","unstructured":"Philipp G\u00f6rz, Bj\u00f6rn Mathis, Keno Hassler, Emre G\u00fcler, Thorsten Holz, Andreas Zeller, and Rahul Gopinath. 2023. Systematic assessment of fuzzers using mutation analysis. In 32nd USENIX Security Symposium (USENIX Security 23). 4535-4552."},{"key":"e_1_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428334"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833751"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238219"},{"key":"e_1_2_2_17_1","unstructured":"Linux Kernel. 2020. Kernel Concurrency Sanitizer (KCSAN). https:\/\/2.zoppoz.workers.dev:443\/https\/docs.kernel.org\/dev-tools\/kcsan.html."},{"key":"e_1_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24018"},{"key":"e_1_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_2_2_20_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security '21)","author":"Li Yuwei","year":"2021","unstructured":"Yuwei Li, Shouling Ji, Yuan Chen, Sizhuang Liang, Wei-Han Lee, Yueyao Chen, Chenyang Lyu, Chunming Wu, Raheem Beyah, Peng Cheng, et al. 2021. UNIFUZZ: A Holistic and Pragmatic Metrics-Driven Platform for Evaluating Fuzzers. In Proceedings of the 30th USENIX Security Symposium (USENIX Security '21)."},{"key":"e_1_2_2_21_1","unstructured":"Linux Kernel. 2019. qmi_wwan: Fix out-of-bounds read. https:\/\/2.zoppoz.workers.dev:443\/https\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux. git\/commit\/?id=904d88d743b0c94092c5117955eab695df8109e8."},{"key":"e_1_2_2_22_1","unstructured":"Linux Kernel. 2020. qmi_wwan: unconditionally reject 2 ep interfaces. https:\/\/2.zoppoz.workers.dev:443\/https\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/ torvalds\/linux.git\/commit\/?id=00516d13d4cfa56ce39da144db2dbf08b09b9357."},{"key":"e_1_2_2_23_1","unstructured":"Linux Kernel. 2025. Linux Kernel CVE information. https:\/\/2.zoppoz.workers.dev:443\/https\/git.kernel.org\/pub\/scm\/linux\/security\/vulns.git."},{"key":"e_1_2_2_24_1","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security 22)","author":"Liu Jian","year":"2022","unstructured":"Jian Liu, Lin Yi, Weiteng Chen, Chengyu Song, Zhiyun Qian, and Qiuping Yi. 2022. LinKRID: Vetting Imbalance Reference Counting in Linux kernel with Symbolic Execution. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22) (USENIX Security '22)."},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/22145.22146"},{"key":"e_1_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473932"},{"key":"e_1_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277272"},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00211"},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3663529.3663800"},{"key":"e_1_2_2_30_1","unstructured":"Linux Test Project. [n. d.]."},{"key":"e_1_2_2_31_1","unstructured":"Linux Test Project. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/linux-test-project\/ltp."},{"key":"e_1_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23404"},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00137"},{"key":"e_1_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464821"},{"key":"e_1_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23368"},{"key":"e_1_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483547"},{"key":"e_1_2_2_37_1","unstructured":"Syzbot. 2016. Syzkaller Dashborad. https:\/\/2.zoppoz.workers.dev:443\/https\/syzkaller.appspot.com\/."},{"key":"e_1_2_2_38_1","unstructured":"Syzkaller. 2019. KASAN: global-out-of-bounds Read in qmi_wwan_probe. https:\/\/2.zoppoz.workers.dev:443\/https\/syzkaller.appspot.com\/bug?extid= b68605d7fadd21510de1."},{"key":"e_1_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623146"},{"key":"e_1_2_2_40_1","unstructured":"Dmitry Vyukov. 2016. Syzkaller. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/google\/syzkaller."},{"key":"e_1_2_2_41_1","volume-title":"Proceedings of the 32nd USENIX Conference on Security Symposium (USENIX Security '23)","author":"Wang Zicheng","year":"2023","unstructured":"Zicheng Wang, Yueqi Chen, and Qingkai Zeng. 2023. PET: prevent discovered errors from being triggered in the linux kernel. In Proceedings of the 32nd USENIX Conference on Security Symposium (USENIX Security '23)."},{"key":"e_1_2_2_42_1","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security '23)","author":"Wu Yuhang","year":"2023","unstructured":"Yuhang Wu, Zhenpeng Lin, Yueqi Chen, Dang K Le, Dongliang Mu, and Xinyu Xing. 2023. Mitigating Security Risks in Linux with KLAUS: A Method for Evaluating Patch Correctness. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security '23)."},{"key":"e_1_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/3698900.3698977"},{"key":"e_1_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489347"},{"key":"e_1_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623188"},{"key":"e_1_2_2_46_1","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security '22)","author":"Zhang Zenong","year":"2022","unstructured":"Zenong Zhang, Zach Patterson, Michael Hicks, and Shiyi Wei. 2022. FIXREVERTER: A Realistic Bug Injection Methodology for Benchmarking Fuzz Testing. In Proceedings of the 31st USENIX Security Symposium (USENIX Security '22)."}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808201","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:55:46Z","timestamp":1782845746000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3808201"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":46,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808201"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3808201","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}