Summary: After Linus’s previous stance that security vulnerabilities are just bugs and don’t require special treatment, the kernel’s new policy is that almost every bug gets a CVE if it has the potential to become a security vulnerability.
Still, 432 in 24 hours is a lot. Looks like someone made their job way easier with AI, however I refuse to believe this is slop, as these are some of the most important maintainers on the planet who wouldn’t just throw AI on reviewing code like that.
Context: https://tuxcare.com/blog/the-great-kernel-cve-flood-of-2024/
Summary: After Linus’s previous stance that security vulnerabilities are just bugs and don’t require special treatment, the kernel’s new policy is that almost every bug gets a CVE if it has the potential to become a security vulnerability.
Still, 432 in 24 hours is a lot. Looks like someone made their job way easier with AI, however I refuse to believe this is slop, as these are some of the most important maintainers on the planet who wouldn’t just throw AI on reviewing code like that.