Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release



When I gave a link to that Linux Magazine article, I didn't bother to insert 
separate links to the other webpages that were mentioned in the article.  
Clicking on those other pages gives additional info, including answering some 
of Rich's points.  Here's some of what those other pages clarify.

First, the actual number is not quite 2,000 CVEs but more like 1,900 CVEs in 
kernel release 7.2.  That is not the number of CVEs found but the number of 
CVEs fixed in 7.2.  1,900 is a pretty high number of CVEs that need fixing.  
But more importantly, the number of CVEs fixed per kernel release has been 
increasing very rapidly over the last 6 months.  In pre-2026 releases of the 
kernel, there tended to be about 500 CVEs fixed per release.  Likewise, 
kernel version 6.19, which was released on Feb 8 of this year, had about 500 
new CVEs fixed.  But then the rate starts to accelerate.  The two subsequent 
versions, 7.0 (released April 12) and 7.1 (released June 14), fixed over 
1,200 new CVEs apiece.  And the version after that, which is actually the 
most recent one, is 7.2, released a few weeks ago on August 16, which fixed 
about 1,900 new CVEs.  All these CVEs were actually judged important enough 
to fix.  We haven't yet exhausted capacity to fix vulnerabilities that are 
being uncovered mostly by AI.  But it is clear that the rate of *discovered* 
CVEs has been increasing rapidly, and if the rate of *discovered* CVEs 
increases further, we are at risk of running out of capacity to fix them.  
Here's Greg Kroah-Hartman's post with a chart:
https://social.kernel.org/notice/B9nU6wnmFvh5atXSG8

Second, bugs are already being triaged by abandoning drivers for relatively 
older devices.  It appears that developers hadn't wanted to abandon these 
drivers yet, but the high pace of AI-detected bugs forced them to abandon 
these drivers and hope that "nobody" was still using them.  That is an 
obvious thing to try when CVEs are being detected at a fast rate and there 
aren't enough kernel developers who can fix all the detected CVEs.  For 
example, back in April Linus Torvalds agreed to pull kernel support for ISDN, 
amateur radio, and other old network devices, so that people could 
concentrate on fixing other CVEs in kernel version 7.1.  But it is a sign 
that the existing group of kernel developers are having trouble keeping up, 
and if the rate of detected CVEs continues to increase, we may reach a point 
where abandoning support for somewhat older hardware isn't enough to cope.  
The pull request that Linus acted on worried about "having a fighting chance 
of surviving the LLM-pocalypse", and also mentioned that their current AI 
system Sashiko/Gemini "finds a lot of real issues."
https://www.phoronix.com/news/Linux-7.1-Removes-Old-Net
https://www.phoronix.com/news/Linux-7.1-PR-Remove-Old-Net

On Fri, Sep 4, 2026, at 12:36 AM, Rich Pieri wrote:
> TL;DR: don't believe the hype
>
> On Thu, 03 Sep 2026 22:32:20 +0000
> "Randall Rose" <rrose at pobox.com> wrote:
>
>> The story mentions that some of these vulnerabilities may be dealt
>> with by dropping support for drivers for relatively old hardware, but
>> still, that's a lot of vulnerabilities to handle.
>
> Or a meaningless statistic. How many of these 2000-odd vulnerabilities
> are actually exploitable? How many of these exploitable vulnerabilities
> are practical as opposed to theoretical to exploit, and under what
> conditions? What are the consequences of a successful exploit? Without
> answers to these and related questions it's nothing more than a number
> in a vacuum.
>
> I'm sure some of these 2000 bugs are severe enough to warrant immediate
> remediation but how many? One? Five? A dozen? More than this? Let's say
> it's 12. A tool which can reliably find *and single out* these 12 bugs
> requiring immediate remediation is a far more valuable tool than one
> which buries these 12 bugs in a bucket of 2000 bug reports.
>
> But "our AI tools found 12 critical bugs and we fixed them before
> release" doesn't draw the clicks like "AI found 2000 bugs in the Linux
> kernel".
>
> -- 
> \m/ (--) \m/
> _______________________________________________
> Discuss mailing list
> Discuss at lists.blu.org
> https://lists.blu.org/mailman/listinfo/discuss



Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org