Urgent.News

What's breaking now, across thousands of outlets.

Tech

Debian's latest kernel security update has 1,313 reasons to patch

AI-assisted bug hunting adds to maintainers' workload, while broad CVE rules help explain the sprawling tally

Debian's latest kernel security update has 1,313 reasons to patch

Debian's most recent Linux kernel security update contains an impressively high number of 1,313 CVE identifiers, revealing the growing role of AI-assisted vulnerability discovery. The DSA-6528-1 Linux security advisory, released on September 29, addresses the kernel package version 6.12.111-1 for Debian 13, also known as Trixie.

Released nine days after the upstream kernel 6.12.111, Debian 13.7 highlights the fast-paced nature of Linux kernel development, which averages around nine changes per hour and 30 bug fixes daily. As the Linux kernel project became a CVE Numbering Authority in February 2024, kernel maintainer Greg Kroah-Hartman explained the CVE assignment process.

Although a CVE identifier provides limited information about severity or exploitability, the sheer number of CVEs in this update suggests an increased reliance on AI bots for bug hunting and potentially fixing issues. The Linux security mailing list has already been overwhelmed by AI assistance, according to an article published in May.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Monday 5 October →