Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release



I'm not sure this reasoning is conclusive -- it seems to imply that "number 
go down" must be true no matter what.  That's as implausible as a doomster's 
assumption that "number go up" is inevitable.

Currently the number of CVEs discovered per release has been increasing over 
the last 6 months, by a factor of 4.  I expect that this increase will 
continue at least for the near future, but I don't know by how much.  We will 
have to see if the capacity of kernel developers to fix bugs is adequate to 
deal with not just the future increase in AI-detected CVEs per release. We 
are already at the point where bug fixes are effectively being triaged by 
discarding support for relatively older drivers sooner than the kernel 
developers would normally want.  If that form of triage isn't enough in 
future, and recruiting new kernel developers isn't adequate, harsher forms of 
triage may be next.  There is still some possibility that in the coming 
years, the vulnerability of Linux distros to KNOWN types of CVEs may grow.

In addition, it seems quite possible that sophisticated adversaries such as 
governments and Cellebrite-like firms and sophisticated AI swarms acting on 
their own may have access to more sophisticated AIs that can find CVEs more 
rapidly than any tool available to the Linux kernel developers.  So the 1,900 
CVEs that were fixed in kernel version 7.2 may be the tip of the iceberg 
compared to the larger attack surface of vulnerabilities that were known to 
attackers OTHER than the kernel developers.

The overall lesson is that, contrary to what some FOSS advocates years ago 
liked to say about open-source operating systems being more or less 
impervious to hacking threats, the FOSS world is far from being immune to the 
contemporary reality that cyber-attack remains much easier than cyber-defense.

On Fri, Sep 4, 2026, at 8:16 AM, Rich Pieri wrote:
> On Fri, 04 Sep 2026 01:34:44 +0000
> "Randall Rose" <rrose at pobox.com> wrote:
>
> [snip]
>
> There are a finite number of bugs in any given proposed kernel release.
> If tools find 2000 of them, and they are remediated, then there are
> 2000 fewer bugs in that release. It's a zero-sum game, or a close
> approximation, where Team LLM Apocalypse steadily loses as the number
> of discovered and discoverable bugs goes down.
>
> New code will introduce new bugs. It's still a zero-sum game: the
> number of new bugs introduced in new code is finite. These bugs will be
> discovered, fixed, and number go down.
>
> But like I wrote last night, "number go down" doesn't draw the clicks
> and the ad revenue.
>
> -- 
> \m/ (--) \m/
> _______________________________________________
> Discuss mailing list
> Discuss at lists.blu.org
> https://lists.blu.org/mailman/listinfo/discuss



Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org