16 comments

  • drfloyd51 9 minutes ago
    Is it possible that some of these bugs were already exploited by governments? And AI might help use close of that kind of thing? (And expose other kinds of things , in a kind of AI arms race?)
    • bhouston 0 minutes ago
      Probably. Organizations specializing in hacking are probably having a great time hacking everything and installing permanent presence. It is probably like a gold rush period.
  • john_strinlai 16 minutes ago
    note that _any_ bugfix is assigned a cve, which makes for big numbers.

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    https://docs.kernel.org/process/cve.html

    "number of cves" is a useless metric, especially when it comes to the kernel.

    • SAI_Peregrinus 6 minutes ago
      Tautologically every bug can legitimately be assigned a CVE, since every bug prevents some feature from working as intended. It's therefore a denial of service, which by the definition of the CVE system using CVSS means every bug is at least a 1/Low level vulnerability to CVSS v4.0.

      If you're willing to stretch, missing but planned features also deny the use of said features since they haven't been added yet, and so are CVSS 1/Low vulnerabilities.

      Resume-driven development for security researchers has never been easier!

    • rerdavies 7 minutes ago
      With particular emphasis on "almost any bug might be exploitable".
  • tetrisgm 44 minutes ago
    That’s probably a great thing. The initial friction of AI overwhelming projects certainly sucks, but once there are better processes to deal with them it’s going to strengthen the quality of so many projects!
    • SchemaLoad 36 minutes ago
      Long term we will end up with software with no low hanging fruit exploits left. But right now we are in a period where low hanging fruit is everywhere and it's easier to exploit systems than ever before.
  • userbinator 22 minutes ago
    Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

    Remotely or locally exploitable? This is very lacking on information.

    • SchemaLoad 19 minutes ago
      If they were bugs of consequence you could expect each one to get it's own domain with a scary name and a logo.
      • adastra22 11 minutes ago
        Unfortunately no, there are a lot more that fly under the radar.
  • modeless 1 hour ago
    1,313 vulnerabilities, to be precise.
    • nathell 18 minutes ago
      In Heroes of Might & Magic 3, “several” means 5–9. 10–19 is “pack”, 20–49 is “lots”, 50–99 is “horde”, 100–249 is “throng”, 250–499 is “swarm”, 500–999 is “zounds…” and 1000+ is “legion”.

      I suggest this post be renamed “A legion of vulnerabilities has been discovered…”

  • BobbyTables2 48 minutes ago
    Are these primarily AI-assisted findings ?

    Seems like an enormous increase over 2024 and 2025.

    • ganelonhb 27 minutes ago
      Yes, naturally. It’s a brave new world.
  • sva_ 38 minutes ago
    Seems like the CVE sequence has, for the first time, reached >100000 this year (Which does not imply 100k vulns though)

    Apparently by late summer this year, there were already more vulnerabilities found than in all of 2025.

  • DominoTree 59 minutes ago
    I was looking earlier and the majority of these do not have a CVSS score assigned to them yet, but a lot of them that did were >7.0 (although I suppose by nature that the more impactful CVEs are going to be scored more quickly)
  • thallium205 1 hour ago
    Pretty much any kernel bug gets a CVE by default now, right?
    • wjholden 58 minutes ago
      Is that all there is here? The quantifier "several" did not prepare me for the wall of CVE numbers in this list.
      • vdfs 19 minutes ago
        https://docs.kernel.org/process/cve.html states that because almost any kernel bug can potentially compromise system security, the CVE team acts with extreme caution and labels nearly all bug fixes with a CVE
    • seba_dos1 27 minutes ago
      Yes. It looks funny, but it's a nothing burger.
    • slopinthebag 43 minutes ago
      yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln

      one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

      • akersten 38 minutes ago
        > perhaps c should get a __UNSAFE { } block,

        I think the convention for this is at the filesystem level and most programmers use the `.c` suffix to indicate it

        • slopinthebag 21 minutes ago
          in that case we need a block of system memory marked as unsafe so i can run these programs in it encapsulated

          perhaps we could call it a sedimentchest?

  • imoverclocked 37 minutes ago
    Is there a way to know if a particular vanilla kernel has a particular CVE addressed? Unhelpfully, the ChangeLog-* only seems to contain sporadic references to CVEs.
  • embedding-shape 28 minutes ago
    "Several" feels a bit of an understatement, there are 1313 CVEs listed on that page!

    Wonder how many of these NSA and others been sitting on, for how long and how many are still there? I guess the silver lining with the aixplosion of CVEs is that software eventually will get more secure.

    • SchemaLoad 20 minutes ago
      Something to keep in mind is the Linux project registered as an authority to create their own CVE numbers in 2024. Previously the majority of bugs would just be fixed without note unless there was a demonstration that it could be exploited.

      Now they just give almost every bug a CVE number.

    • vdfs 20 minutes ago
      Any kernel bug gets a CVE even if it's not really a vulnerability or can be exploited
  • jeffbee 9 minutes ago
    Linux has never, at any point in history, lacked flaws that could be exploited to escalate privileges. The only question has been how well-known the flaws were, and when. The count of latent local privilege escalation bugs has never been zero.
  • jaimex2 25 minutes ago
    s/discovered/fixed
  • SadErn 37 minutes ago
    AI is finishing the job that Snowden started. If we backfill all these holes privacy can be preserved.
  • ofjcihen 55 minutes ago
    [dead]