- cross-posted to:
- linux@sh.itjust.works
- cross-posted to:
- linux@sh.itjust.works
cross-posted from: https://infosec.pub/post/49770060
Comments
Context: https://tuxcare.com/blog/the-great-kernel-cve-flood-of-2024/
Summary: After Linus’s previous stance that security vulnerabilities are just bugs and don’t require special treatment, the kernel’s new policy is that almost every bug gets a CVE if it has the potential to become a security vulnerability.
Still, 432 in 24 hours is a lot. Looks like someone made their job way easier with AI, however I refuse to believe this is slop, as these are some of the most important maintainers on the planet who wouldn’t just throw AI on reviewing code like that.
Just for those who don’t know: Every bug or issue in the Kernel is treated as a CVE. That’s why the number seems to that high.
To my understanding, these are confirmed vulnerabilities and have been resolved in 7.1. I have not checked all of them but didn’t find any CVEs without a note on the fixed kernel version.
Most definitely AI, but why is Greg posting it like this? Wouldn’t it be more natural to post sequentially after having verified what the LLM spit out? This seems like he’s testing Linus after his pro-AI message…
@onlinepersona @floofloof It is a list of already confirmed and fixed problems. Every link has set of links to patches that fixes the problem.
Isn’t every CVE already confirmed to be a problem?
Sure, but the fix isn’t written at the same time as the CVE is it? I might be wrong.
I’d expect the fixes to come sequentially, not in a batch with all having the same timestamp
In some previous statements Torvalds said that all Ai based CVEs are handled differently and need to be disclosed publicly immediately. His argument was that if someone found a vulnerability or an issue with a LLM, then others will probably too. So hiding it just caused multiple reports of the same issue, because usually CVEs are hidden until they are solved. That might explain why all of them are dumped immediately.
For someone who
lurksroams that much, and makes baseless claims liberally, you appear to be missing a lot of basic info, like responsible disclosure, gap periods, or the private mailing list every distro is on which allows them time to ship fixes before the vulnerabilities are announced.Maybe that’s why they asked the question
While it is indeed amusing to think that perma-online often-wrong people are geniuses who perfected the execution of Cunningham’s Law. In reality, they couldn’t be further from that. And everything they write is second or third hand anyway, often sourced from the bottom-of-the-barrel corners of the internet.
Watch them call me AI again because of the “while…they”, after the magnificent leap of detecting my supposed anti-immigrant sentiment (which is a dog-whistle for “fervent racist” of course).
Am I lurking or making many baseless claims? Can’t be both. You sound like the “dey teyk r jaaaabs” types that think immigrants are lazy and taking jobs at the same time.
Reading your post history is looking a troll up the rear.
So you’ve noticed this user lurking a lot and also making lots of claims? Indeed, up === down.
In interviews Greg has also shown to have a positive stance towards AI usage in the kernel







