114 points•luispa•about 4 hours ago•68 comments•

68 comments

john_strinlaiabout 2 hours ago
note that _any_ bugfix is assigned a cve, which makes for big numbers.

>“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

https://docs.kernel.org/process/cve.html

"number of cves" is a useless metric, especially when it comes to the kernel.

SAI_Peregrinusabout 2 hours ago
Tautologically every bug can legitimately be assigned a CVE, since every bug prevents some feature from working as intended. It's therefore a denial of service, which by the definition of the CVE system using CVSS means every bug is at least a 1/Low level vulnerability to CVSS v4.0.

If you're willing to stretch, missing but planned features also deny the use of said features since they haven't been added yet, and so are CVSS 1/Low vulnerabilities.

Resume-driven development for security researchers has never been easier!

viraptor40 minutes ago
> It's therefore a denial of service

That doesn't follow. In the extremely simple example, an adding service returning 1+1=3 has a bug, but it's not a possible DoS situation at all.

> missing but planned features also deny the use of said features

That's not what DoS is.

This whole situation with CVE assigning comes from the whole process being far from ideal. But it doesn't mean it's completely useless and doesn't follow any rules at all.

mbreese30 minutes ago
> note that _any_ bugfix is assigned a cve

I do find it interesting though, that in the interest of transparency, every bugfix gets a CVE. Which ends up being a huge number… which will ultimately yield a more insecure environment as we’re getting conditioned to ignore/discount CVEs by the volume.

Over-reporting in this case seems to risk being counterproductive.

socializer19 minutes ago
It's not very interesting. Linus, and by extension the Linux kernel, long had a dismissive attitude toward security research. This is basically a childish swing from one extreme (nothing gets a CVE) to another (everything gets a CVE).

Kernel development is well-funded, both via grants and by direct employment at big tech companies, and if they wanted to properly triage and annotate vulnerabilities, and provide reasonable assessments of what is or isn't likely to be a security risk, they absolutely could. They could almost certainly go to Google and say "we need two people full-time on your payroll for this" and they would get it.

I don't want to dunk on them too much because they're generally doing God's work, but these absolutist security stances are not worth being taken seriously.

Gigachad20 minutes ago
Depends on the end consumers stance on security. I've watched it shift from "Only update if we can prove we are impacted" to "Update everything immediately just in case".

The frequency and severity of cyber attacks has increased to the point a much more cautious approach has become common. It's also easier to sell this work to management when you can point at the security tab on some tool and say "Look we need to patch these CVEs"

theteapot38 minutes ago
I've been following these announcements for a few years. This is the most CVEs I've seen in one by a wide margin, although there have been some big sets coming through for things like chromium, openssl. I agree it's mostly meaningless without context. So what's the context? Who/what found all these bugs?
rerdaviesabout 2 hours ago
With particular emphasis on "almost any bug might be exploitable".
SoftTalkerabout 1 hour ago
Even a bug-free program might be exploitable.
Fordecabout 1 hour ago
This is great, more access did provide more eyes on these problems.

But, does that all of these being found now call into question, not the open source model logic itself, but the ability of human eyes to find security issues? These vulnerabilities have been sitting here for however long, but how many thousands of humans did not find them before AI?

spoaceman7777about 1 hour ago
The threshold for Microsoft and Apple to actually report vulnerabilities is MUCH MUCH higher than for Linux, and open source as a whole. They generally only disclose issues in Windows and macOS that are quite serious and impactful.

For Linux, the threshold is nearer to the point of it being questionable whether a bug is even exploitable on a real production distro, compiled and run with any sort of sane configuration.

SchemaLoadabout 1 hour ago
Even before AI we have known that no one is smart enough to write bug free C. And with every bug being a launch platform for a full exploit it's become a big deal.
1over137about 1 hour ago
No one is smart enough to write bug free in any language.
0c3ca8343 minutes ago
AI levels the playing field; it's incredibly good at finding the bugs.
tetrisgmabout 2 hours ago
That’s probably a great thing. The initial friction of AI overwhelming projects certainly sucks, but once there are better processes to deal with them it’s going to strengthen the quality of so many projects!
SchemaLoadabout 2 hours ago
Long term we will end up with software with no low hanging fruit exploits left. But right now we are in a period where low hanging fruit is everywhere and it's easier to exploit systems than ever before.
somenameformeabout 1 hour ago
That relies on a major assumption that current systems are finding the vast majority of all possible exploits out there. This assumption itself would assume that either current LLMs are near perfect, or that the peak difficulty for exploits was just above human capability (which is where LLMs currently are). I think both of those assumptions are very likely false. If so then we'll see indefinitely ongoing exploit discovery LLMs improve their capabilities.

Long term I suspect that the purpose of the digital domain is going to end up being rethought. For instance connecting critical infrastructure to the internet has always been a terrible idea, and LLMs will just make that even more clear.

catlifeonmarsabout 1 hour ago
That’s assuming we’re not adding software defects at the same pace, but I imagine we are generating a lot more defects than are being discovered at the moment.
modelessabout 3 hours ago
1,313 vulnerabilities, to be precise.
nathellabout 2 hours ago
In Heroes of Might & Magic 3, “several” means 5–9. 10–19 is “pack”, 20–49 is “lots”, 50–99 is “horde”, 100–249 is “throng”, 250–499 is “swarm”, 500–999 is “zounds…” and 1000+ is “legion”.

I suggest this post be renamed “A legion of vulnerabilities has been discovered…”

drfloyd51about 2 hours ago
Is it possible that some of these bugs were already exploited by governments? And AI might help use close of that kind of thing? (And expose other kinds of things , in a kind of AI arms race?)
bhoustonabout 1 hour ago
Probably. Organizations specializing in hacking are probably having a great time hacking everything and installing permanent presence. It is probably like a gold rush period.
sippingabonedryabout 1 hour ago
Will everyone chill the F out for a minute?

These get released every few weeks. Tons of CVEs. If a kernel developer farts in the forest, does anyone hear it?

August saw separate Debian kernel updates released four days apart. Does anyone even reboot that often?

I have three kernels installed over the last 45 days or so and I probably missed a few.

tclancy31 minutes ago
Regarding the fart question, it depends on the audio driver and the underlying codec. While you would think “free as in beer” would make for truly resonant flatulence, only truly letting loose (plus a Bic lighter) brings real enlightenment.
nightflyabout 1 hour ago
I've been doing Linux sys-admin work for 10+ years. Used to be I could read the full report on what ever vulnerabilities came out and triage which servers needed to be updated now and which could wait. A few years ago notifications started having so many it would take more time/effort to read everything than it would to patch everything. With this notification there's even ten times more...
SoftTalkerabout 1 hour ago
We're considering weekly reboots at work now with the pace of kernel updates coming out, and the speed with which vulnerabilities are getting exploited.

Read the full thread on Hacker News →

Related stories