r/technology 15h ago

Security Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are "completely overwhelmed" by CVE finds

https://www.tomshardware.com/software/linux/linux-kernel-nears-2-000-cves-per-release-as-ai-bug-hunters-scour-40-million-lines-of-code-maintainers-say-they-are-completely-overwhelmed
1.7k Upvotes

274 comments sorted by

View all comments

Show parent comments

14

u/BastetFurry 14h ago

I do, state funded kernel devs.

22

u/dangerbird2 14h ago

The kernel itself is pretty well funded with pretty much every major tech company contributing money and developer talent. The real issue is smaller projects that are integral parts of the linux ecosystem, but not part of the kernel project itself. See the XZ backdoor incident

8

u/captainstormy 14h ago

I was about to say this myself. I'm a software engineer and Linux System Admin. Been working in the industry over 20 years now. I've been paid by a lot of companies (some you know, many you don't) to submit code to the kernel. Sometimes other parts of a Linux system but mostly the Kernel.

3

u/ignatzami 13h ago

This. The left pad problem writ large. The big visible pieces get funded. The solo devs supporting a package with millions of weekly downloads on NPM don’t get much, if anything.

1

u/nox66 2h ago

It's ironic. Major corporations often benefited from open source, including NPM, PyPI, curl, etc., even without contributing back, and somehow this was relatively sustainable until the corporations themselves created the means for it to not be so. Pretty telling of the situation overall.

3

u/happyscrappy 12h ago

Which state?

Maybe Larry Ellison could call up Trump and come up with a list of 100 trustworthy system devs to take over the linux kernel.

Big Balls can be the director.

-4

u/LegitimateCopy7 14h ago

do you want to uhm... think it through? like actually?