Commenters debated a recent large list of Linux kernel CVEs and whether it reflects a real spike in security problems or simply CVE inflation. John_strinlai, thallium205, SAI_Peregrinus and mbreese argued that the CVE process now assigns identifiers to many routine fixes, making raw counts a misleading metric and risking CVE fatigue. Others, like intrepidsoldier and romaniitedomum, blamed AI: some said AI is exposing systemic fragility or accelerating both vulnerability discovery and insecure code generation, while biwills and tetrisgm suggested AI-assisted discovery could be a net positive by finding buried issues that would otherwise be sold as zero-days. Exabrial and DominoTree emphasized that many entries affect drivers or require special configurations, so impact varies and severity assessments are still pending.
Participants also split on remedies and implications. Snvzz and jaypatelani pushed for fundamentally different architectures - formally verified microkernels or Ada/SPARK-based systems - to eliminate whole classes of bugs, while slopinthebag and SchemaLoad focused on memory safety and C’s limits. NoPicklez warned that identifying vulnerabilities is easier than fixing complex attack chains, and drfloyd51, embedding-shape and bhouston worried about state actors exploiting latent bugs. Others, like Fordec and senectus1, saw broader disclosure as potentially strengthening open source security over time once processes adapt.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.