r/technology 8h ago

Security Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are "completely overwhelmed" by CVE finds

https://www.tomshardware.com/software/linux/linux-kernel-nears-2-000-cves-per-release-as-ai-bug-hunters-scour-40-million-lines-of-code-maintainers-say-they-are-completely-overwhelmed
1.3k Upvotes

241 comments sorted by

1.4k

u/Humpaaa 8h ago

I don't care about the millions of AI found CVEs. The important line is: Maintainers are overwhelmed.

We need to realize how much of our everyday infrastructure is not adequately supported, and find ways to divert ressources to these positions.

257

u/mydogeatspoops 7h ago

I’m sure there is an oligarch or commercial interest that would love to support the project for just a few extra lines of code here or there.

82

u/WeekendCautious3377 5h ago

Used to work in software security. First team to get re-orged / layoffed during boom time. Execs never invest in it until something goes horribly wrong

24

u/SnooSnooper 5h ago

And even then they only really care for a couple months/quarters, after which their goldfish-like attention span demands they shift resources to whatever new shiny all the other execs are talking about

6

u/userhwon 4h ago

Execs are the horribly wrong.

2

u/MammothUnique4147 2h ago

This is the way 

98

u/jethroguardian 7h ago

Melinda Gates could do the funniest thing...

48

u/mayorofdumb 6h ago

MacKenzie would do it to spite Bezos.... shes the reason why they are trying to get rid of marriage equality.

5

u/SeeMonkeyDoMonkey 5h ago

Why do you think Bezos would be unhappy at improvements to Linux?

7

u/atxweirdo 3h ago

It’s not that he would be unhappy but it would be taking power from him and the opportunity to make a lasting change for good which seems to be antithetical to his motivations of late

1

u/fredy31 10m ago

Isnt it exactly how we almost had a linux backdoor a year ago?

Dude maintaining a library thanklessly for 20 years suddenly had a great volunteer to help with the load.

That volunteer then tried to sneak in a backdoor that would let him break openssh and then any linux machine.

354

u/krileon 7h ago

"We found 1000 CVE!" "Ok, and how are they exploited?" "Well the system needs to have already been exploited" ... this has also been the recent "AI FOUND VULNERABILITY" trend.. they're 99% of the time nothingburgers.

196

u/TOGFIAVDF 7h ago edited 6h ago

Yeah, I'm in cybersec and this is a pretty apt description of what these CVE notices are really saying.

Most of these vulnerabilities are only vulnerabilities when the system is already compromised. They still need to be addressed, but it isn't Swiss cheese.

Though, it should be noted that vulnerabilities are still vulnerabilities. Just because a vuln needs an already compromised system to be exploited doesn't mean said vuln can't be used to push an attack further.

edit: wording

16

u/silversurger 5h ago

That's probably part of why they're so overwhelmed. They have to classify, assess the amount of work and prioritize thousands of CVE notices. And until it has been classified, everything is urgent. This all happens before even any code has been written.

2

u/TOGFIAVDF 5h ago

Yep, it has to be brutal.

50

u/krileon 7h ago

You're not wrong, but a vulnerability that already requires a compromised system goes from "WE NEED TO PATCH NOW" to "maybe sometime next year?" on priority. Regardless still requires a human to deal with and wastes a bunch of time having to look over these.

20

u/TOGFIAVDF 6h ago

That's what I'm saying.

Hopefully they're using an effective framework to sort their tasks.

9

u/CocodaMonkey 4h ago

Already exploited system is doing some heavy lifting here. In many cases already exploited means they need user level access. On a server that is generally the same thing but on a user device it can mean they can bypass locks that have been imposed on them specifically.

10

u/Cow_says_moo 5h ago

I'm not sure if we can still think that way. AI isn't just good at identifying individual vulnerabilities, but also at chaining relatively minor vulnerabilities together into exploits which could be more threatening than initially expected.

7

u/sickofthisshit 4h ago

There's an architectural aspect, though. "Getting root" at one place should be fixed at the one place.

If a stupid bot then tries to exhaustively search all the ways you are fucked once you have root, well, that's the whole kernel, right?

Unless the bots deeply understand this kind of thing (as opposed to understanding the shape of a vulnerability and the shape of an exploit), it creates an enormous amount of noise.

1

u/Sislar 3h ago

A vulnerability can also be a permissions escalation. So a valid user can get admin privileges so not on a compromised system but on a system someone already had legitimate access.

1

u/TOGFIAVDF 2h ago edited 2h ago

Fair distinction, though that falls in its own incident category. Ultimately, anyone with meaningful access to a system is a weak point.

Without giving too much info, a company I've worked for had everything on a single network share. The only restricted folders were individual user desktops, and those were accessible by a handful of authorized users.

Engineering drawings, vendor and order information, sales orders, source code to software, etc. Literally everything accessible by anyone on the network. To make it worse, each users' workstation was a Windows OS with an admin account and access to PowerShell.

It's amazing they didn't deal with more cyber incidents. I guess being a smaller company helped in that regard.

1

u/Bubbagump210 53m ago

Issue: when root can run rm -fr /

1

u/Due-Consequence9579 12m ago

Also since the kernel operates at such high trust they use a very liberal definition of cve. Anything out of spec is considered a CVE.

10

u/QuackQuackViech 3h ago

Yeah I hate this shit too. "Oh no a new CVE has been found, in my report it says 9.9 and its colored red. Red I tell you!! Fix immediately."

Then you read the fine print and it says "Attacker must be omniscient being with direct console access and all admin passwords, then he can inject commands to change the clock."

30

u/PaulCoddington 7h ago

Unfortunately, devs end up wasting time triaging them.

8

u/digiorno 5h ago

That said , this sort of layered attack is exactly how some of the most impressive cyberattacks in history have succeeded. Most places don’t have anything to worry about. But you can bet places like the NSA are trying to harden their systems asap.

10

u/Valuable-Worth-1760 6h ago

Critical and high vulns are also exploding everywhere. Mythos' submissions were not inherently lower severity than human submissions.

19

u/krileon 6h ago

Those can get drowned out by 1000+ pointless CVE for vulnerabilities that require a system to have already been heavily compromised. The noise will cause real threats to be missed.

3

u/Valuable-Worth-1760 6h ago

Yeah sure, I just get the impression that folks are distracting from any discussion about wtf do we do about capable AI (risk of competence) with what do we do with slop AI (risk of incompetence). Both real, but if there are capable models than those can also be used to triage slop. Vs if all models are just slop, then we need to focus on getting models to be better/more competent- but that "solution" would make the risks of competence much... worse. Which is why we need to take them seriously, instead of downplaying/distracting from model competence. The general public does not think AI is competent (at anything).

2

u/Humpaaa 6h ago

Still, all those nothingburgers take time to search througha s a maintainer.

1

u/technobrendo 2h ago

Don't they also have a severity score? That makes a huge difference

1

u/[deleted] 5h ago

[deleted]

3

u/WealthyMarmot 4h ago

this is how a lot of the most devastating cyberattacks work nowadays. Rarely is there a single vulnerability that will open the door to a hardened system, so attackers chain together multiple exploits to work their way into a privileged position.

48

u/Stilgar314 7h ago

Relevant xkcd

31

u/captain150 7h ago

Man and that comic was years before the xz utils state sponsored supply chain attack. It's amazing the maintainer stood strong against it as long as he did.

11

u/Stilgar314 7h ago

Yeah, from all the relevant xkcd, this happened to be the most relevant.

27

u/romario77 7h ago

this has to be a one time thing - these CVEs were created over many years of development and only now are noticed because of AI.

Once fixed I don't expect as many to appear again. There is no easy solution to this, but I expect better and more robust software after this is sorted out.

19

u/otherwiseguy 7h ago

The only way out is through.

9

u/araujoms 6h ago

I don't think so. The Linux kernel is extremely large. I think if you keep digging you'll keep finding vulnerabilities. In some obscure hardware used by few people, but still. If the maintainers have to look at them they get bogged down all the same.

In the past nobody found vulnerabilities in the less-used parts of the kernel because nobody bothered to look. But now with AI people can spend a few minutes and say "Look, ma, I have a CVE!"

I think what will happen is that people will stop caring, and only serious vulnerabilities affecting the core parts of the kernel will be addressed.

7

u/kenlubin 6h ago

The alternative seems to be that the Linux kernel is cutting support for outdated networking technologies. Maybe of the bugs are in the drivers for outdated technology that no one uses anymore, so there aren't very many eyes on the code.

1

u/Mr_ToDo 5h ago

I'd be a great day to be a kernel that doesn't need to take all that hardware support internally

1

u/Ok_Turnover_1235 2h ago

That's the beauty of running gentoo

1

u/daHaus 6h ago

That's very optimistic

14

u/Senior-Albatross 7h ago edited 7h ago

We'll do what we always do: ignore the obvious problems until something catastrophic happens and then address it afterwards at much greater cost. 

1

u/PlanPlus8582 29m ago

How else are we going to sell solutions without problems?  /s

6

u/Atlatica 5h ago edited 4h ago

I mean there is the wider problem too, which is that there isn't a constant stream of junior-mid level developers using open source to grow their portfolio any more.  There are just pre-AI mid-senior devs, and there are grads with Claude subscriptions and entry level retail 9-5s who vibe code video games in their spare time.

2

u/ilep 4h ago

Cutting from education is a big problem the way I see it. Things are only getting more complicated to learn and there is not enough time to learn basics properly any more. And if you are programming on kernel you do need to understand hardware as well since that is what kernel deals with.

3

u/bwrca 6h ago

There's trillion dollar companies that built and continue to build their products on top of this platform, but the platform itself lacks adequate engineering support. Not surprised.

17

u/ignatzami 7h ago

That's the Achilles heel of open source. And I don't have a solution for it.

71

u/mad_marble_madness 7h ago edited 7h ago

If you think most commercial software is better staffed, then you have never worked for a commercial software company…

7

u/ignatzami 6h ago

Decade at Microsoft. I know.

5

u/ilep 5h ago

And if you think commercial software has poor security you have never seen industrial automation..

13

u/BastetFurry 7h ago

I do, state funded kernel devs.

20

u/dangerbird2 7h ago

The kernel itself is pretty well funded with pretty much every major tech company contributing money and developer talent. The real issue is smaller projects that are integral parts of the linux ecosystem, but not part of the kernel project itself. See the XZ backdoor incident

7

u/captainstormy 7h ago

I was about to say this myself. I'm a software engineer and Linux System Admin. Been working in the industry over 20 years now. I've been paid by a lot of companies (some you know, many you don't) to submit code to the kernel. Sometimes other parts of a Linux system but mostly the Kernel.

3

u/ignatzami 6h ago

This. The left pad problem writ large. The big visible pieces get funded. The solo devs supporting a package with millions of weekly downloads on NPM don’t get much, if anything.

2

u/happyscrappy 5h ago

Which state?

Maybe Larry Ellison could call up Trump and come up with a list of 100 trustworthy system devs to take over the linux kernel.

Big Balls can be the director.

→ More replies (1)

2

u/Nemesis_Ghost 7h ago

It's not just the maintainers, it's also the downstream dependents. My company, like many, are dependent on a lot of OSS software packages in our builds. We have scanning software checking our packages for vulnerabilities & then blocking builds if one is found. It has gotten to the point that my teams can't go a single day w/out having spend an hour or more per app updating & retesting due to vulnerabilities.

2

u/baylonedward 6h ago

Isn't parts of EU shifting to Linux? Maybe they can make money grants related to Linux.

2

u/pbrutsche 4h ago

You're assuming that these "millions" of CVE are legit. The maintainers are overwhelmed with just verifying the CVEs.

The companies that Anthropic granted access to Mythos says it has a 30% true positive rate.

3

u/Humpaaa 4h ago

You're assuming that these "millions" of CVE are legit.

I'm not. That's why i say i don't care about them. Most of them will be low quality. But the maintainers still need to verify every single one. That alone binds a lot of ressources.

2

u/TeutonJon78 2h ago

Also goes back to the "easier to destroy than create" adage.

Setting AI loose on a code base takes relatively no human effort.

Sorting through the output, determining actual severity, and then creating the fix/redesign and getting it responsibly deployed is a huge amount of actual human effort.

1

u/LlorchDurden 5h ago

Boss, I'm tired 🫠

1

u/JamesLahey08 3h ago

How often do you donate to Linux developers?

1

u/brakeb 2h ago

before you throw 'moar peoplezzzz' at the problem, perhaps removing 30ish years worth of cruft, unsupported code, maintainerless tech, break out the kernel to allow for more modular driver management, etc...

removing esoteric shit for people to find CVEs against will probably go a long way to stop being 'overwhelmed'. THey seem to be embracing AI to assist with this.

1

u/brakeb 5h ago

the problem is that maintainers are getting fixes for ancient fucking code that is stuck in the kernel that no one uses anymore or hasn't seen a code update in 5+ years and are expected to fix it.

Rip out old drivers, old services, cruft that no one has touched in years. Feature freeze the kernel until Linus and team has a chance to scrub the kernel and remove old shit. if you're still the gray hair that 'needs' your PCMCIA eth card, you figure out how to make your shitty laptop work with it.

-11

u/TFenrir 7h ago

This will necessitate the automation of software delivery. These PRs will soon have to be handled by AI, autonomously.

I think people will get mad at me for saying this, because they don't want it to be true, but I'm not saying it because I think it's fun and cool and sexy, it's just literally what has to happen if you want to have secure software.

We are months away from autonomous AI swarms, frontier and open weight/source, running rampant through the Internet.

We will very soon see official info released about the next waves of models (likely Astra and the 5.1 line of a claude) and I really want to encourage people to pay attention to these and consider the ramifications of their capabilities.

13

u/neppo95 7h ago

How so when the AI will also merge things that create bugs. AI is great but until it doesn’t regularly make mistakes, an autonomous process would do a lot of harm.

6

u/Legionof1 7h ago

Yep, it has to be better than a human when it comes to this stuff and it just isn’t yet, faster, but not more accurate.

-3

u/TFenrir 7h ago

There are already pipelines in world class software organizations that are currently doing this. Using the very best models, sure, but yes this is already happening.

5

u/neppo95 7h ago

Okay? Doesn’t make it any better.

1

u/TFenrir 6h ago

I mean, I'm not sure what you are saying - AI will definitely merge in bugs. But we already have processes for this because we also merge in bugs. The speed and capability of these models are currently at the point where the net benefit is so great that some of the best developers in the world do not look at the code anymore.

What I'm saying is - your concern is already no longer a concern. It in some ways (we always have had to deal with bugs) has never been a concern.

1

u/neppo95 6h ago

I mean, the evidence directly counters your statement. Microsoft has one of those autonomous processes. Guess what? Windows hasn’t been buggier in its existence and is pretty much falling apart. No, bottomline it is net negative still.

4

u/TFenrir 6h ago

... This isn't evidence. This is just you saying things that you want to be true. Where is the evidence for any assertion in this statement of yours?

1

u/neppo95 4h ago

So pure logic is out of the window I see. Company changes way of working drastically. Products suddenly are broken as fuck. Hmm, would there be a link between the two, I wonder. It's allowed to think you know.

2

u/TFenrir 4h ago

LLMs have only been capable enough that anyone would even try to do what I am describing, in the last 6 months dude.

→ More replies (0)

2

u/Expensive_Finger_973 7h ago

So what happens when the AI is finding bugs and exploits in the code base it wrote and it just ends up being a snake eating its own tail?

3

u/TFenrir 7h ago

Software development is already all about finding the bugs you already wrote. Everyone writes bugs and then fixes them.

1

u/Expensive_Finger_973 5h ago

I know, but what happens when the AI is writing all of the code? Perfect code, or endless churn of AI code with bugs and other AI code to patch it and be found to have bugs later on?

2

u/TFenrir 5h ago

I think by the end of the year, the default assumption will be that AI written code will be better than human code, in almost every context. They will autonomously find and fix bugs faster than we will notice, as they work on swarm where each agent works 10x faster than a human.

It's just... Hard for people to wrap their heads around this.

1

u/bensquirrel 4h ago

There are cost barriers to this at the moment. Frontier labs can do this because their token cost is cheap. Open weight models still need to run somewhere so they are not zero cost either.

1

u/DeterminedThrowaway 6h ago

They downvoted him because they hated the truth. I don't see a single viable alternative offered

0

u/Acrobatic-Ice-5877 6h ago

  I don't care about the millions of AI found CVEs. The important line is: Maintainers are overwhelmed.

You should care. Most of the world runs off Linux.

0

u/psioniclizard 5h ago

One of the points of AI is to replace the need for maintainers.

If AI was as amazing as tech bros say, the first thing they will do is remove Linus or just make  tech bro folk of linux and not push anything up stream.

Seeing as everyone other developer apparently can be replaced, linux maintainers will be no different.

0

u/No-Marionberry-772 4h ago

tbh, I'm just happy to have the ability to tell linx elitists to piss off when they argue that Linux is more secure.

it has always been the case that It is less popular, not more secure.

→ More replies (4)

181

u/Big_District8152 7h ago

We also receive lots of AI generated pentest finding. 80% of them are plain bullshit and the people "create" them don't even read them. They just simply press send.

42

u/Orzorn 7h ago

It makes some endpoints look hideous if you just do what the AI says. If/else checks and custom regex EVERYWHERE.

3

u/Fried_puri 7h ago

If it works it works…until it doesn’t.

1

u/fredy31 4m ago

Yeah what i heard is lots of people improvise themselves programmers and submit bug reports that are complete shit

413

u/avatar_one 8h ago

Well, that's what you get when you have an open source code, which is actually good, as they will eventually get fixed :)

I dare not to think how many would have been found if Windows source code was open :D

129

u/baldycoot 8h ago edited 8h ago

lol probably need a black hole to power the compute required to fix an O/S windows.

18

u/Chronic_In_somnia 8h ago

If they open the source code we’d all see a moment like in the matrix when the cat walks by and Neo has déjà vu.  Reality would lag.

5

u/Nannautu 2h ago

Windows runs amazingly well if you consider the fact there is so much bloatware

1

u/Loa_Sandal 5h ago

Reminds me of some old video where they bypassed the Windows login by somehow printing the login prompt. Can't seem to find the video now though, but it was weird.

1

u/ar34m4n314 4h ago

I mean they are trying. Microsoft is part of project glasswing (Claude Mythos access), and they purchased a nuclear reactor to power datacenters (though technically for other stuff).

0

u/avatar_one 8h ago

It would cause a heat death of the universe :D

32

u/tralltonetroll 7h ago

Of course there are tons of such issues found. Microsoft also runs AI engines on their own code even if the code is not open.

And unless they are nuts, they also ask the AI engines for help to prioritize.

11

u/WealthyMarmot 4h ago

Microsoft is a core member of Project Glasswing, which is Anthropic’s invite-only program to grant unrestricted access to Mythos for defensive purposes, and you can bet they’re also part of the OpenAI equivalent.

1

u/DenialGene 6h ago

This is true.

5

u/xelrach 6h ago

Microsoft has access to Mythos. They are also overwhelmed dealing with all of the security reports.

7

u/emanuele232 7h ago

I agree, i do expect 0 days for closed source software to increase at a similar rate, and there you could have a lot of problems

3

u/Etiennera 7h ago

Afaik right now LLMs aren't trained on much machine code yet but there will come a day when an LLM can decompile and translate machine code, then a lot will change. At least at first it will be fairly resource intensive and not too hard to lock down.

5

u/Iggyhopper 6h ago

I do RE (revese engineering) and depending on the prompt, LLMs will give you injection code and help optimize assembly. (I needed the space so instead of wiping 300 bytes, I optimized it by half to make space for jumps.)

3

u/OrphisFlo 6h ago

They can already reason pretty well around machine code, or use assistance from a decompiler to quickly make sense of code.

They are not able to analyze fully a well obfuscated binary, but they can go pretty far otherwise, which is relevant for Windows. And it's not necessarily a token black hole that will cost millions per binary. Since a lot of Windows parts are already documented, it's easy enough to analyze anything from there.

2

u/No-Snow-7618 7h ago

would still be “lossey”

compiler optimization is some magical gremlin shit sometimes

3

u/Etiennera 7h ago

You would not necessarily get the original, but you'd get something that produces the same bytecode, which is good enough for most applications you'd want it for.

1

u/avatar_one 7h ago

Yeah, and that is actually a much bigger issue imo.

2

u/Ilikeyounott 8h ago

Do LLMs care if the source code is open or not? Like sure, seeing the source code is ideal and easier, but couldn't they just analyze the machine code? Or use a decompiler to turn it into ie. mangled c code that is a mess for human to make sense, but not so for LLMs?

22

u/electricity_is_life 7h ago

LLMs are powerful, but they aren't magic. They can certainly analyze binaries and decompilations, but the number and quality of findings will be lower compared to real source code.

1

u/Legionof1 7h ago

They don’t care… they can read source or binary and as long as they are trained on it they can read it. They can even decompile it into source again. How well they do it is another question entirely.

6

u/avatar_one 7h ago

I believe that no LLM could (at least for now) reverse engineer the closed source Windows code that is compiled and shipped.

2

u/OrphisFlo 6h ago

It depends which parts. From experience, they are doing fine, especially since a lot of the high level surfaces are documented, you are rarely fully in the dark.

3

u/slightly_drifting 7h ago

They are obfuscating and stripping symbols and shit. Def not gonna happen until they get trained on source leaks.

3

u/Ilikeyounott 6h ago

I threw winnat.sys at Claude, and it had no problem reverse engineering it using ghidra, and telling me how it worked. Sure, when it tells me where stuff happens, it's in opaque things like FUN_18001b110 since no debugging symbols, but it has no problem understanding the decompiled code (but it seems to be slower, I guess it has to work for it). 

1

u/ARTIFICIAL_ARGUMENT 7h ago

Yea Microsoft would collapse overnight, having huge market share dependent on their closed source software is almost all their value 

2

u/WealthyMarmot 4h ago

eh the software itself is not their core offering. It’a all the hosted infrastructure and the MSP ecosystem and the million other ways they’re tightly coupled into enterprise IT systems. We’re a long way from the Windows 95 days, when their product really was mostly just the set of floppy disks that installed the OS.

2

u/amakai 7h ago

Think of code as additional and very useful metadata on what's going on, sort of "comments" on what the code is supposed to be doing.

Consider this example. AI sees that a routine is opening a file and writing a fixed number into it. That looks like garbage without context. With context, that could be some integration with an external tool, but for that you ideally need docs, but source code naming also helps.

2

u/MartinMystikJonas 7h ago

Compiled code lacks tons of important context. You can see what is executed but in most cases you need additional info to know it it is executed as intended or not.

-2

u/Legionof1 7h ago

That’s a human outlook because we can’t hold the entire application in our brain at once. AI can potentially fly past that barrier because it can wholisticly understand the application from its source.

2

u/MartinMystikJonas 7h ago

No it cannot. LLMs have limited context windows. No chance to squeze even small part of OS source code there. And building of understanding of something as complex as OS from source code alone is way beyond capabilities of current frontier models. Not to mention that even tbat would not be enough to be sure what was original intent of that code.

-1

u/Legionof1 6h ago

The Linux kernel is roughly 40m lines of code, there are context windows big enough for that… what you can buy and what exists are also two massively different things. 

→ More replies (6)

2

u/romario77 7h ago

LLMs are trained on source code, not on machine code, so yes, they do care and do better if they have source code.

They can potentially analyze the machine code as well - it's a tougher task though. This actually has to be done and it's not equivalent to analyzing code - there are bugs in compiler and some of the vulnerabilities are not actually in the source code but only appear under some circumstances when the code is compiled.

1

u/Senior-Albatross 7h ago

They haven't been trained on machine code. That's not what's available as training data. 

Actually, if we were smart, we might really optimize some machine code and then train these things on it directly. That way we could get better optimized outcomes if no one is ever going to read the code anyway. 

4

u/BastetFurry 7h ago

I had Claude dissect an old game to find out how the assets are organized and loaded, he went to town with Radare2 on those old DOS binaries and found out how stuff works.

Now i have a nice document and the next weekend i have some time i might start adding Vision A 5th Dimension Utopia, that subsidized by the Sparkassen and LBS adventure game in that swimming tower, to ScummVM with the reversed info i got there. Vision 1 and 2 seem to use the same engine, so that would add both games.

2

u/OrphisFlo 6h ago

I regularly point Claude at games to extract data out of them that is otherwise hardcoded in the binary or internal data files. It's always able to figure it out in the end.

People are really underestimating what they can do.

173

u/slightly_drifting 7h ago

I can back this up. Some of these AI "pentests" and AI "bypasses" are being presented as individual CVE's that are complete bullshit, or are because the system it was run on was simply misconfigured and there's no CVE required. So now i'm looking at a mountain of bullshit, that's covering small molehills of real shit.

Now I know how those Pokemon card graders feel.

18

u/pbrutsche 4h ago

Anthropic Mythos (the one that Anthropic said was too dangerous to release) has only a 30% true positive rate.

1

u/WealthyMarmot 4h ago

Look at the changelogs for any one of a thousand large OSS projects these days - full of real CVE fixes, many discovered via AI. Look at how often OpenAI researchers are credited in Apple’s recent security bulletins (which have been unusually frequent, because AI is finding so much shit). There’s no sweeping this under the rug.

There’s a real problem with noise-to-signal ratio, for sure, but any org that doesn’t use AI defensively is going to get run over by the black hats.

36

u/Zeausideal 7h ago

The sad thing is that they send out a lot of "vulnerabilities" searches using AI to claim rewards, which is making it harder to report serious problems.

5

u/ImUrFrand 1h ago

the bug hunters are not doing so because of good nature, they are specifically going for bug bounties, which is why there are so many reports recently.

some software maintainers have killed their bug bounty programs because of this.

they have also noted that 95% of the bug reports weren't valid.

tl:dr; it's people looking for easy money.

4

u/virtualadept 1h ago

How many of them are meaningfully exploitable (e.g., are they "You have to be on the box already, have root access, and if exploited it causes a lockup or reboot?")

How many of them don't make it into the binary because they get elided or optimized away by the compiler at build time?

How many of them are hallucinations from the LLM?

12

u/ConSaltAndPepper 6h ago

What do I need to do to become a maintainer. I'm not a software developer but I love to learn. I have years of experience in IT and Data engineering and architecture.

What's the best way for me to begin to be able to properly help?

6

u/Cantabulous_ 6h ago

And, what do we think all of the GenAI providers and hyperscalers use - could it be Linux? Perhaps they might have some resources to spare.

3

u/Tipcat 1h ago

I have high doubts every vulnerability reported by AIs are actually serious or even 'real'.
They could use a vastly different categorization method and one that would never pass for human eyes.

Knowing what some AIs have suggested when writing code before just reinforces this.

2

u/IriFlina 43m ago

I’m willing to bet 99% of the findings are false positives

12

u/captainstormy 7h ago

It's important to point out that AI can scan the Linux Kernel because it's open source. So finding bugs is something it can do and it's actually good. They can be prioritized and fixed that way.

That just can't happen with a closed source OS like Windows or Mac.

8

u/dislikes_redditors 7h ago

It does and has been happening with Windows and Mac

4

u/captainstormy 7h ago

Yes, you can still do pen tests. But you can't just scan and analyze the source code which is far more effective.

5

u/dislikes_redditors 5h ago

They have access to their own source, and access to the same AI models. They are doing their own analysis the same way that others are analyzing OSS

0

u/captainstormy 5h ago

Sure. But that all happens behind closed doors so we have no idea how many findings there are or how serious they are.

3

u/ar34m4n314 3h ago

Not knowing is very different from isn't happening. Microsoft is scrambling to keep up. They know a lot of their code has leaked and that their customers are often security sensitive, its a business issue for them. Not a big MS fan, but realistically they are probably working very hard at this because they have a financial incentive to.

2

u/WealthyMarmot 3h ago

Both companies publish fairly comprehensive security bulletins. They’re not going to say, “we ran X tool and found Y number of bugs,” but you can go through the CVEs and get a pretty good sense of what they’re finding.

1

u/Disma 1h ago

Microsoft also likes to leave the patching to AI

5

u/CondiMesmer 5h ago

How many of them are actually real?

2

u/ar34m4n314 3h ago

A significant amount. Here is a writeup by the people who make Firefox: The zero-days are numbered 

1

u/IriFlina 44m ago

Firefox devs drank the AI Kool-Aid so they can’t be trusted

6

u/ea_man 6h ago

It's funny because someone thought that with AI doing computer stuff they could fire some people, it's the opposite.

It's the weak links in a production chain lesson.

→ More replies (2)

2

u/No-Invite-7826 1h ago

What percentage of those CVEs are even valid? I know for a fact a lot of them end up being hallucinated and wastes of time.

3

u/I_am_le_tired 6h ago

People in this thread who think it's mostly bullshit issues are missing what's happening.

I watched a 30mn interview with a Mozilla senior dev working with Mythos who said the number of critical bugs and zero days that Mythos was finding was crazy, and that their bug fix rate was multiplied by 20x while they rush to patch the worse vulnerabilities before models as powerful or more as Mythos become available to everyone (including hackers) in a few months.

The companies that won't use Mythos super quickly super extensively will become prey to a wave of hacking agents that is hard to comprehend.

The next few years will be rocky as shit

5

u/Upbeat-Statement2725 3h ago

No. Mozilla is an "ai-first" company with a major financial stake. Man will say anything when his salary is involved.

As an example. OpenAI and HuggingFace weren't even using standard tools from decades ago. There should have been a pager setup to alert anyone of the test bed accessed the internet. And it should have been blocked immediately. Nobody bothered. This is a great argument that AI breeds complacency.

We had static testing tools to perform these tests, and alerting tools when they go wrong, decades ago.

HuggingFace magically found their attack the same day they sent a price to Jensen Huang. Weird coincidence. 

0

u/Limp_Classroom_2645 7h ago edited 7h ago

why not also use ai to organize and fix those vulns, at least have a rough patch for each vulnerability proposed by AI and let humans review and adapt the patches?

This is not a bad thing, this is actually a good thing. all those vulnerabilities detected by ai could be zero days being exploited today by hackers and governments, now those vulnerabilities are visible and can be acted upon.

22

u/_5er_ 7h ago

Making a report doesn't automatically make it a valid report. There are a lot of cases, where reportes don't even bother to check if LLM report actually makes sense.

Sending a report back to LLM, to validate it doesn't really work. LLM can help you a lot yeah, but a person still needs to decide if it's valid.

→ More replies (4)

3

u/OrphisFlo 6h ago

You can use them to some degree, but it's always a cost / effort balancing act. You could have Mythos try to create a PoC for each of them to see if they're true exploitable ones, a bug or just an impossible edge case.

It would take a while, but it's probably fine, machines will just work while you watch YouTube, but the cost will be astronomical. So you can only use some light classification with a cheaper model, some will be a "definite yes", a lot will be a "maybe" because it's hard to prove a negative (that it's not exploitable), some will be a "probably no".

But are you confident enough in the tooling yet to blanket reject an issue without a human expert looking into it? Do you want to be responsible for a massive breach caused by ignoring a valid report?

7

u/Jmc_da_boss 7h ago

"Why not also make the process even more draining and annoying for the maintainers"

Do yall people hear yourselves?

→ More replies (1)

1

u/Blando-Cartesian 6h ago

These people are not maintaining a minecraft mod or some irrelevant social media hellhole. What they do needs to work and changes that require everything else to be updated can’t happen.

-2

u/SweatyAd8914 7h ago

Because the maintainers of Linux are turbo OCD and would rather launch the nukes than change a single pointer in a kernel level script.

0

u/marmaviscount 7h ago

When everything is worked through we will see a much more secure system, this is really good news

20

u/mekkr_ 7h ago edited 7h ago

No, we’ll likely miss actually severe and impactful vulnerabilities because they’ve been drowned in a sea of “ummm, actually” vulnerabilities that are more code quality issues or extreme edge cases than anything that’s actually worth being concerned about.

I’ve been in cybersecurity for a decade and AI has just shifted the problem from discovery to triage. Like everything else it touches it creates slop that needs slop to fix it. The infinite slop circus continues.

-12

u/marmaviscount 7h ago

The ai is also great at triage, you're desperate to dismiss this brilliant development in technology and it's just silly

9

u/mekkr_ 7h ago

I work a bug bounty program for a global company as part of my duties. If you think AI is good at triage I’ve got a datacenter to sell you.

-3

u/grchelp2018 6h ago

then you've not engineered the system properly. We use ai for triage. We also know that a lot of people just aim their ai at us and tell it to find something. So we've got detailed instructions telling the agent exactly what we need for a bug report, what we need for our agent to be able to reproduce it etc etc. And then once the bug report lands, our agent does triage, spins up vms to try and reproduce it, asks clarifications etc before finally deciding whether to surface it to us. Its an engineered pipeline not just an agent operating naked but it works well.

6

u/mekkr_ 6h ago

I was talking about the triage AI system built by the market leader who we use as a vendor, not our system.

Regardless, you’re suggesting a solution to a problem we didn’t have. All of this is for the sake of using AI instead of objectively superior human expertise.

-1

u/marmaviscount 5h ago

Sure, random Redditor knows what all the big companies who release peer reviewed science on the subject don't...

I'm sorry but the compulsive liars on this site just make it impossible for me to believe these sorts of empty claims that go against everything everyone who is verifiably in the industry is saying and what all the science points to - either you're awful at your job and don't understand what everyone else is doing to get such good results or you're one of the many people who will spin any story to try and be prove their 'side' right.

4

u/smith7018 7h ago

Selfishly, it also means that locked down devices based on some of these open systems will be easier to hack. I'm looking at the PS5, Switch 2, Android devices, iOS devices, etc.

3

u/doommaster 7h ago

The PS5 runs on FreeBSD (sure it's also getting linted, but way less intensive)

2

u/wrgrant 6h ago

Does it really? Not a console gamer, but we ran FreeBSD on some servers when I worked for a company ages ago. I liked it. Now that you have told me this I know its still running nearby on the console my wife and nephew play on. Thats kind of cool in a very nerdy way.

3

u/doommaster 6h ago

Yeah, because the freeBSD license allows them to not publish their modifications to the system, which makes it harder to exploit.

4

u/wrgrant 6h ago

Right. Plus its a pretty stable base to build anything on overall when you know exactly the hardware you need support for etc.

0

u/oscarolim 3h ago

Thats a joke right? There hasn’t been a single play station that hasn’t been exploited.

1

u/doommaster 3h ago

Of course not, but not having access to the hypervisor source code makes exploiting a lot more complicated

0

u/[deleted] 7h ago

[deleted]

1

u/marmaviscount 7h ago

They just fixed the most bugs ever, I get not reading the article but at least read the headline lol

1

u/questron64 34m ago

And how many of those are real? AI will confidently declare it found a vulnerability and write a full detailed report but it also tells me to glue cheese to pizza. They wire them up in these test harnesses so they can run code and that is better than the old hallucinations directly into your veins but it's still by no means fixed.

0

u/EdgiiLord 7h ago

I will laugh after this whole AI craze when people will realize most of these are hallucinated because most devs wouldn't understand what the AI outputed and how they left Linux with less hardware compatibility and more hallucinated AI "fixes".

1

u/That-Interaction-45 6h ago

We are in an era of increasing insecure software until we hit peak and come down the other side. I have been updating everything I can get my hands on.

1

u/uniquelyavailable 6h ago

I agree, and this situation will continue to worsen. I am dealing with this on a daily basis. Send help lol

1

u/ReidenLightman 4h ago

No worries. Just have the 2 million free volunteer contributors audit all the code and submit vulnerabilities. Right?... Right? 

-1

u/brakeb 5h ago

"completely overwhelmed" = we've never lived in a time where people actually had the time to look at our code, and AI is kicking our asses and showing our code quality has been shit for decades

We finally have the "many 👀 make for more secure code" that people have preached for decades about open source that they wanted, and this is the result of that

0

u/brakeb 5h ago

and they absolutely need to kick older shit out of the production releases... if you still 'need' that ISA sound card, then you'll build it yourself.

1

u/WealthyMarmot 4h ago

Yep I think the end result is a bunch of crusty old hardware drivers get purged. It’ll be annoying for some people, but it’s a net positive.

-3

u/SweatyAd8914 7h ago

I’m more impressed how LLMs were able to find these gaps in the first place. Either we’ve known about these vulns, and were too lazy/overwhelmed, and/or LLMs genuinely found these gaps and nobody ever knew.

Either way, congrats to Linux for patching these sooner than later. Looking at you Windows/Mac

15

u/Pawtuckaway 7h ago

Or LLMs hallucinated a bunch of CVEs that don't exist. My work heavily uses LLMs for many things and every PR has about 10 comments from an LLM reviewer. 90% of those comments are irrelevant or just flat out wrong.

-2

u/SweatyAd8914 5h ago edited 5h ago

If you’re not using Claude, your team is irrelevant and false positives are to be expected. I work F100 with strict compliance standards and 80% of flagged CVEs are legit. Sounds like a skill issue.

I’ll also reiterate, you’re correct on small nits, but big issues flat out wrong. I additionally could care less what the other morons here think.

→ More replies (1)

5

u/Wizzarkt 7h ago

I read an article somewhere saying that the bast majority of those "bugs" were not real or at least not reproduceable so some Linux mainteiners are super mad because they get flooded with junk.

→ More replies (2)

0

u/No-Snow-7618 7h ago

watch it just be a string function affecting buffer overflow

-6

u/poulain_ght 7h ago

Still nothing compared to microslop vulnerabillities.

-1

u/daHaus 6h ago

The important number is how many of those vulnerabilities were added by AI?

0

u/phantom_1996 7h ago

my old laptop kernel updater freaked out with so many alerts too

0

u/freekarl408 5h ago

Im getting crushed at work rn

0

u/userhwon 4h ago

Okay. But fix them.

0

u/BriefCautious7063 4h ago

I don't care what the CVE's are, I care about how exploitable they may or may not be. If a CVE just does something small it's irrelevant, but if a big one comes out it's more important to mention what it does than "look how many there are". On a scale of " make text look a little funny and do nothing else" to "zero-day kernel level remote code execution actively being exploited", all of it can be called a CVE and it goes without saying that the nature and exploitability of the vulnerability matters. If an AI flags a buffer overflow by just pointing out the usage of "unsafe" C functions, but fails to validate there being any way to input arbitrary data into those functions due to other safeguards, there's not even a vulnerability to begin with and maintainers still have to manually check thousands of requests. All headlines like this do is advertise AI as being smart enough to find thousands of vulnerabilities, scrutinize millions of lines of code, and be better at it than the overwhelmed maintainers; it doesn't acknowledge how many severe vulnerabilities were found, how many were patched, whether they're overwhelmed by work or by spam, etc