r/technology 15h ago

Security Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are "completely overwhelmed" by CVE finds

https://www.tomshardware.com/software/linux/linux-kernel-nears-2-000-cves-per-release-as-ai-bug-hunters-scour-40-million-lines-of-code-maintainers-say-they-are-completely-overwhelmed
1.7k Upvotes

274 comments sorted by

View all comments

-8

u/SweatyAd8914 14h ago

I’m more impressed how LLMs were able to find these gaps in the first place. Either we’ve known about these vulns, and were too lazy/overwhelmed, and/or LLMs genuinely found these gaps and nobody ever knew.

Either way, congrats to Linux for patching these sooner than later. Looking at you Windows/Mac

17

u/Pawtuckaway 14h ago

Or LLMs hallucinated a bunch of CVEs that don't exist. My work heavily uses LLMs for many things and every PR has about 10 comments from an LLM reviewer. 90% of those comments are irrelevant or just flat out wrong.

-6

u/SweatyAd8914 12h ago edited 12h ago

If you’re not using Claude, your team is irrelevant and false positives are to be expected. I work F100 with strict compliance standards and 80% of flagged CVEs are legit. Sounds like a skill issue.

I’ll also reiterate, you’re correct on small nits, but big issues flat out wrong. I additionally could care less what the other morons here think.

0

u/Pawtuckaway 5h ago

You could care less? I guess you must care a little then.

-3

u/red75prime 13h ago

Just use more AI

The team has also increasingly had to fight AI with AI. It has now secured access to multiple frontier models to help review patches and filter out hallucinated results, and is considering pushing more routine administrative work onto LLMs in subsequent development cycles.

5

u/Wizzarkt 14h ago

I read an article somewhere saying that the bast majority of those "bugs" were not real or at least not reproduceable so some Linux mainteiners are super mad because they get flooded with junk.

-1

u/Diarmundy 14h ago

Windows and Mac are closed source so its much harder for AI to find vulnerabilities

2

u/WealthyMarmot 10h ago

Both Apple and Microsoft are heavily using these tools internally. There’s a reason Apple’s been pumping out so many security updates lately, relative to their usual cadence.