50 points luispa 1 hour ago 25 comments

modeless 1 hour ago | parent

1,313 vulnerabilities, to be precise.

thallium205 50 minutes ago | parent

Pretty much any kernel bug gets a CVE by default now, right?

wjholden 45 minutes ago | parent

Is that all there is here? The quantifier "several" did not prepare me for the wall of CVE numbers in this list.

vdfs 6 minutes ago | parent

https://docs.kernel.org/process/cve.html states that because almost any kernel bug can potentially compromise system security, the CVE team acts with extreme caution and labels nearly all bug fixes with a CVE

slopinthebag 30 minutes ago | parent

yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln

one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

akersten 25 minutes ago | parent

> perhaps c should get a __UNSAFE { } block,

I think the convention for this is at the filesystem level and most programmers use the `.c` suffix to indicate it

slopinthebag 8 minutes ago | parent

in that case we need a block of system memory marked as unsafe so i can run these programs in it encapsulated

perhaps we could call it a sedimentchest?

seba_dos1 14 minutes ago | parent

Yes. It looks funny, but it's a nothing burger.

DominoTree 46 minutes ago | parent

I was looking earlier and the majority of these do not have a CVSS score assigned to them yet, but a lot of them that did were >7.0 (although I suppose by nature that the more impactful CVEs are going to be scored more quickly)

BobbyTables2 35 minutes ago | parent

Are these primarily AI-assisted findings ?

Seems like an enormous increase over 2024 and 2025.

ganelonhb 14 minutes ago | parent

Yes, naturally. It’s a brave new world.

tetrisgm 31 minutes ago | parent

That’s probably a great thing. The initial friction of AI overwhelming projects certainly sucks, but once there are better processes to deal with them it’s going to strengthen the quality of so many projects!

SchemaLoad 23 minutes ago | parent

Long term we will end up with software with no low hanging fruit exploits left. But right now we are in a period where low hanging fruit is everywhere and it's easier to exploit systems than ever before.

sva_ 25 minutes ago | parent

Seems like the CVE sequence has, for the first time, reached >100000 this year (Which does not imply 100k vulns though)

Apparently by late summer this year, there were already more vulnerabilities found than in all of 2025.

imoverclocked 24 minutes ago | parent

Is there a way to know if a particular vanilla kernel has a particular CVE addressed? Unhelpfully, the ChangeLog-* only seems to contain sporadic references to CVEs.

crtasm 20 minutes ago | parent

Clicking them here lists specific kernels, is that enough to tell you?

https://security-tracker.debian.org/tracker/source-package/l...

imoverclocked 14 minutes ago | parent

That's useful if you run a Debian-packaged kernel.

Searching around, the best I have found so far for vanilla kernels is: https://linuxcvetracker.com

It does require a little clicking around to get all the info I want though. Time to pull out curl+awk! :)

embedding-shape 15 minutes ago | parent

"Several" feels a bit of an understatement, there are 1313 CVEs listed on that page!

Wonder how many of these NSA and others been sitting on, for how long and how many are still there? I guess the silver lining with the aixplosion of CVEs is that software eventually will get more secure.

SchemaLoad 7 minutes ago | parent

Something to keep in mind is the Linux project registered as an authority to create their own CVE numbers in 2024. Previously the majority of bugs would just be fixed without note unless there was a demonstration that it could be exploited.

Now they just give almost every bug a CVE number.

vdfs 7 minutes ago | parent

Any kernel bug gets a CVE even if it's not really a vulnerability or can be exploited

jaimex2 12 minutes ago | parent

s/discovered/fixed

userbinator 9 minutes ago | parent

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Remotely or locally exploitable? This is very lacking on information.

SchemaLoad 6 minutes ago | parent

If they were bugs of consequence you could expect each one to get it's own domain with a scary name and a logo.