Vulnerability-Affected Versions Identification: How Far Are We?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Xingchu, Liu, Chengwei, Cao, Jialun, Xiao, Yang, Cai, Xinyue, Li, Yeting, Shi, Jingyi, Sun, Tianqi, Huo, Haiming Chen ang Wei
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909778116083712
author Chen, Xingchu
Liu, Chengwei
Cao, Jialun
Xiao, Yang
Cai, Xinyue
Li, Yeting
Shi, Jingyi
Sun, Tianqi
Huo, Haiming Chen ang Wei
author_facet Chen, Xingchu
Liu, Chengwei
Cao, Jialun
Xiao, Yang
Cai, Xinyue
Li, Yeting
Shi, Jingyi
Sun, Tianqi
Huo, Haiming Chen ang Wei
contents Identifying which software versions are affected by a vulnerability is critical for patching, risk mitigation. Despite a growing body of tools, their real-world effectiveness remains unclear due to narrow evaluation scopes often limited to early SZZ variants, outdated techniques, and small or coarse-grained datasets. In this paper, we present the first comprehensive empirical study of vulnerability affected versions identification. We curate a high quality benchmark of 1,128 real-world C/C++ vulnerabilities and systematically evaluate 12 representative tools from both tracing and matching paradigms across four dimensions: effectiveness at both vulnerability and version levels, root causes of false positives and negatives, sensitivity to patch characteristics, and ensemble potential. Our findings reveal fundamental limitations: no tool exceeds 45.0% accuracy, with key challenges stemming from heuristic dependence, limited semantic reasoning, and rigid matching logic. Patch structures such as add-only and cross-file changes further hinder performance. Although ensemble strategies can improve results by up to 10.1%, overall accuracy remains below 60.0%, highlighting the need for fundamentally new approaches. Moreover, our study offers actionable insights to guide tool development, combination strategies, and future research in this critical area. Finally, we release the replicated code and benchmark on our website to encourage future contributions.
format Preprint
id arxiv_https___arxiv_org_abs_2509_03876
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Vulnerability-Affected Versions Identification: How Far Are We?
Chen, Xingchu
Liu, Chengwei
Cao, Jialun
Xiao, Yang
Cai, Xinyue
Li, Yeting
Shi, Jingyi
Sun, Tianqi
Huo, Haiming Chen ang Wei
Software Engineering
Identifying which software versions are affected by a vulnerability is critical for patching, risk mitigation. Despite a growing body of tools, their real-world effectiveness remains unclear due to narrow evaluation scopes often limited to early SZZ variants, outdated techniques, and small or coarse-grained datasets. In this paper, we present the first comprehensive empirical study of vulnerability affected versions identification. We curate a high quality benchmark of 1,128 real-world C/C++ vulnerabilities and systematically evaluate 12 representative tools from both tracing and matching paradigms across four dimensions: effectiveness at both vulnerability and version levels, root causes of false positives and negatives, sensitivity to patch characteristics, and ensemble potential. Our findings reveal fundamental limitations: no tool exceeds 45.0% accuracy, with key challenges stemming from heuristic dependence, limited semantic reasoning, and rigid matching logic. Patch structures such as add-only and cross-file changes further hinder performance. Although ensemble strategies can improve results by up to 10.1%, overall accuracy remains below 60.0%, highlighting the need for fundamentally new approaches. Moreover, our study offers actionable insights to guide tool development, combination strategies, and future research in this critical area. Finally, we release the replicated code and benchmark on our website to encourage future contributions.
title Vulnerability-Affected Versions Identification: How Far Are We?
topic Software Engineering
url https://arxiv.org/abs/2509.03876