[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
Rich Pieri
richard.pieri at gmail.com
Thu Sep 3 20:36:56 EDT 2026
TL;DR: don't believe the hype
On Thu, 03 Sep 2026 22:32:20 +0000
"Randall Rose" <rrose at pobox.com> wrote:
> The story mentions that some of these vulnerabilities may be dealt
> with by dropping support for drivers for relatively old hardware, but
> still, that's a lot of vulnerabilities to handle.
Or a meaningless statistic. How many of these 2000-odd vulnerabilities
are actually exploitable? How many of these exploitable vulnerabilities
are practical as opposed to theoretical to exploit, and under what
conditions? What are the consequences of a successful exploit? Without
answers to these and related questions it's nothing more than a number
in a vacuum.
I'm sure some of these 2000 bugs are severe enough to warrant immediate
remediation but how many? One? Five? A dozen? More than this? Let's say
it's 12. A tool which can reliably find *and single out* these 12 bugs
requiring immediate remediation is a far more valuable tool than one
which buries these 12 bugs in a bucket of 2000 bug reports.
But "our AI tools found 12 critical bugs and we fixed them before
release" doesn't draw the clicks like "AI found 2000 bugs in the Linux
kernel".
--
\m/ (--) \m/
More information about the Discuss
mailing list