Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ruohonen, Jukka, Abdullahi, Sani, Tiwari, Abhishek
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915497436512256
author Ruohonen, Jukka
Abdullahi, Sani
Tiwari, Abhishek
author_facet Ruohonen, Jukka
Abdullahi, Sani
Tiwari, Abhishek
contents Motivated by software maintenance and the more recent concept of security debt, the paper presents a time series analysis of vulnerability patching of Red Hat's products and components between 1999 and 2024. According to the results based on segmented regression analysis, the amounts of vulnerable products and components have not been stable; a linear trend describes many of the series well. Nor do the amounts align well with trends characterizing vulnerabilities in general. There are also visible breakpoints indicating that the linear trend is not universally applicable and that the growing security debt may be stabilizing.
format Preprint
id arxiv_https___arxiv_org_abs_2509_13117
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
Ruohonen, Jukka
Abdullahi, Sani
Tiwari, Abhishek
Software Engineering
Cryptography and Security
Motivated by software maintenance and the more recent concept of security debt, the paper presents a time series analysis of vulnerability patching of Red Hat's products and components between 1999 and 2024. According to the results based on segmented regression analysis, the amounts of vulnerable products and components have not been stable; a linear trend describes many of the series well. Nor do the amounts align well with trends characterizing vulnerabilities in general. There are also visible breakpoints indicating that the linear trend is not universally applicable and that the growing security debt may be stabilizing.
title Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2509.13117