Surge in Linux Kernel CVEs

432 Kernel CVEs in a Single Day Strain Linux Administrators

Backdoor, Linux, Linux security, Linux backdoor, Velvet Ant, linux login hack, hackers manipulate Linux login systems with backdoors, decade-long Linux cyber espionage campaign exposed, Linux Login, Hacker
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Stanislaw Mikulski / Shutterstock.com

Over 432 CVEs were published for the Linux kernel in just 24 hours. The surge is driven by review backlog processing and AI-assisted bug reports.

Within just over 24 hours, more than 430 new Common Vulnerabilities and Exposures (CVEs) were registered for the Linux kernel. The high volume sparked discussions among system administrators regarding the feasibility of managing individual security notices. A major driver behind the rising number of reported software bugs is the increased use of AI-assisted tools and large language models for source code analysis. As early as May, Linus Torvalds noted that AI-generated bug reports were making the management of the kernel security mailing list difficult, as automated systems continuously identify flaws in the code.

Ad

Jan Schaumann expressed his concerns on the OSS Security mailing list regarding the handling of such high report volumes: “I understand the position that CVEs were always a flawed way to track or prioritize security changes… But this onslaught really shows it’s not feasible to attempt to prioritize individual kernel changes. I’m not sure what to do here going forward.”

Statement by Greg Kroah-Hartman on the Publication Surge

Lead kernel maintainer Greg Kroah-Hartman clarified that the sudden spike was due to catching up on a review queue that had accumulated over several weeks of straight conferences and vacations. He pointed out that the volume of reported vulnerabilities is not a phenomenon unique to the Linux kernel, but rather forces organizations everywhere to re-evaluate their update procedures. The kernel developer strongly advocated for continuous system updates:

“This is what the kernel developer community recommends and supports. If you want support from us, do this. Just use Debian or Yocto as their security practices are amazing.”

Ad

Greg Kroah-Hartman, Lead kernel maintainer

Commenting on attempts to selectively patch individual CVEs, Kroah-Hartman noted: “Good luck with that!”

Recommendations for Update Strategies and Automation

Kroah-Hartman recommends that system operators refrain from manually reviewing individual CVEs and instead rely on automated procedures or deploy complete kernel updates. Enterprise distributions filter security notices automatically by intersecting the files touched by CVEs with the components actually compiled, reducing the review workload to roughly ten percent of the total volume.

Regarding future developments driven by AI tools, Kroah-Hartman emphasized: “The number of llm-found issues is only on the rise right now, it’s going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way.”

(red)

Ad

Weitere Artikel