InquirerPalace confident Marcos to sign 2027 budget before year-endThe Jerusalem PostIAF soldiers reveal air force's initial response to flydubai attempted hijackingRTP DesportoVictor Froholdt, Gianluca Prestianni e Rodrigo Mora finalistas do prémio Golden BoyESPN🏈 CFB Power Rankings: Miami moves up, Missouri, Pitt make listESPN Deportes¿Qué le pasó a Lamar Jackson y cuándo volverá?ZDF heuteAktuelle Pressemitteilungen des ZDF20 Minuten«Wässere meinen Rasen weiterhin» – «Busse an Lohn koppeln»BillboardBillboard’s Music Industry Events CalendarRMF24Maciej Berek czeka na ruch prezydenta. Czy rząd ma plan B?CBS SportsKarl-Anthony Towns says extension negotiations with Knicks 'don't look good' as two sides remain apart on dealSportstarIndian sports wrap, October 5: Himachal CM announces Rs 1 CR each for state’s Asiad gold medal winnersScreen RantThe Batman 2 Filming Paused
The Daily Newsstand · Free, Always
Monday, October 5, 2026

Debian's latest kernel security update has 1,313 reasons to patch

Translate

AI-assisted bug hunting adds to maintainers' workload, while broad CVE rules help explain the sprawling tally

The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers.

The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later.

The Debian security tracker links to descriptions of the individual issues.

REG AD

We have not examined every entry. If we had, this article would not appear until after Debian 13.8 (which is likely to appear later in October), or possibly at some point in 2027. Several checked at random also affect older kernel versions, so the list should not be read as a tally of bugs introduced in 6.12.111.

REG AD

The Linux kernel project became a CVE Numbering Authority (CNA) in February 2024. Back in February this year, kernel maintainer Greg Kroah-Hartman described the Linux CVE assignment process in some detail. He said kernel development averages around nine changes an hour, with a feed of known bug fixes averaging about 30 changes a day providing the basis for the CNA team's review.

The kernel team's policy is to assign CVEs automatically after fixes have reached a stable kernel tree. It takes a deliberately cautious approach because the security implications of a bug may not be apparent when it is fixed. A CVE identifier alone therefore says little about severity or exploitability.

We strongly suspect that this number of CVEs is due to LLM bots doing the bug hunting, and quite possibly doing the bug fixing as well. Linux is not an anti-AI project, and neither is Debian. AI-assisted bug hunting is already swamping the Linux security mailing list, as The Register reported in May.

Kroah-Hartman released kernel 6.12.112 on October 3. Its detailed changelog runs to more than 27,000 lines. With both the rates of change and the sizes of the changes getting so large, it is hard to deny that LLM bot assistance must be very useful to the hard-pressed maintainers. Whether coding bots constitute a net benefit to the projects, to software, or to humanity as a whole remains at best an open question. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.