Urgent.News

What's breaking now, across thousands of outlets.

Tech

Debian's latest kernel security update has 1,313 reasons to patch

AI-assisted bug hunting adds to maintainers' workload, while broad CVE rules help explain the sprawling tally

Debian's latest kernel security update has 1,313 reasons to patch

Debian's latest Linux kernel security update, released on September 29, 2024, includes 1,313 CVE identifiers covering kernel package version 6.12.111-1 for Debian 13, also known as Trixie. The update was issued nine days after the upstream kernel 6.12.111 became available. Debian 13.7 was released earlier on September 12. The Debian security tracker provides links to descriptions of each issue.

Despite the large number of CVEs, several have been assigned to older kernel versions as well, so the figure does not solely represent new bugs introduced in 6.12.111.

The Linux kernel project obtained CVE Numbering Authority (CNA) status in February 2024, following the initiation of automated CVE assignment after kernel fixes reach a stable tree. According to kernel maintainer Greg Kroah-Hartman, Linux kernel development averages around nine changes per hour, with 30 bug fixes occurring daily.

The team employs a cautious approach when assigning CVEs, as the security implications of a fix might not be evident immediately. However, the sheer volume of CVEs suggests that AI-assisted bug hunting and possibly even bug fixing may be playing a significant role in Debian's security efforts. Whether this assistance ultimately benefits Linux, software, or humanity remains open to debate.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Monday 5 October →