Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Pretty much any kernel bug gets a CVE by default now, right?
  • Is there a way to know if a particular vanilla kernel has a particular CVE addressed? Unhelpfully, the ChangeLog-* only seems to contain sporadic references to CVEs.
  • Seems like the CVE sequence has, for the first time, reached >100000 this year (Which does not imply 100k vulns though)

    Apparently by late summer this year, there were already more vulnerabilities found than in all of 2025.

    by sva_
  • Are these primarily AI-assisted findings ?

    Seems like an enormous increase over 2024 and 2025.

  • 1,313 vulnerabilities, to be precise.
  • That’s probably a great thing. The initial friction of AI overwhelming projects certainly sucks, but once there are better processes to deal with them it’s going to strengthen the quality of so many projects!
  • Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

    Remotely or locally exploitable? This is very lacking on information.

  • note that _any_ bugfix is assigned a cve, which makes for big numbers

    >“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

    https://docs.kernel.org/process/cve.html

Explore Birbla archives