Several vulnerabilities have been discovered in the Linux kernel
luispa
217 points
140 comments
October 01, 2026
Related Discussions
Found 5 related stories in 85.7ms across 8,245 title embeddings via pgvector HNSW
- Over 400 Linux CVEs published in the last 24 hours alone aghuang · 72 pts · July 21, 2026 · 67% similar
- OSS-SEC: 432 Linux kernel CVEs (in less than 32 hours) refp · 14 pts · July 22, 2026 · 66% similar
- Microsoft Patches a Record 570 Security Flaws robin_reala · 82 pts · July 14, 2026 · 51% similar
- A CVE Dispute theanonymousone · 186 pts · August 31, 2026 · 51% similar
- Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal pseudolus · 12 pts · August 11, 2026 · 51% similar
Discussion Highlights (20 comments)
modeless
1,313 vulnerabilities, to be precise.
thallium205
Pretty much any kernel bug gets a CVE by default now, right?
DominoTree
I was looking earlier and the majority of these do not have a CVSS score assigned to them yet, but a lot of them that did were >7.0 (although I suppose by nature that the more impactful CVEs are going to be scored more quickly)
BobbyTables2
Are these primarily AI-assisted findings ? Seems like an enormous increase over 2024 and 2025.
tetrisgm
That’s probably a great thing. The initial friction of AI overwhelming projects certainly sucks, but once there are better processes to deal with them it’s going to strengthen the quality of so many projects!
sva_
Seems like the CVE sequence has, for the first time, reached >100000 this year (Which does not imply 100k vulns though) Apparently by late summer this year, there were already more vulnerabilities found than in all of 2025.
SadErn
AI is finishing the job that Snowden started. If we backfill all these holes privacy can be preserved.
imoverclocked
Is there a way to know if a particular vanilla kernel has a particular CVE addressed? Unhelpfully, the ChangeLog-* only seems to contain sporadic references to CVEs.
embedding-shape
"Several" feels a bit of an understatement, there are 1313 CVEs listed on that page! Wonder how many of these NSA and others been sitting on, for how long and how many are still there? I guess the silver lining with the aixplosion of CVEs is that software eventually will get more secure.
jaimex2
s/discovered/fixed
userbinator
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. Remotely or locally exploitable? This is very lacking on information.
john_strinlai
note that _any_ bugfix is assigned a cve, which makes for big numbers. > “Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.” https://docs.kernel.org/process/cve.html "number of cves" is a useless metric, especially when it comes to the kernel.
drfloyd51
Is it possible that some of these bugs were already exploited by governments? And AI might help use close of that kind of thing? (And expose other kinds of things , in a kind of AI arms race?)
jeffbee
Linux has never, at any point in history, lacked flaws that could be exploited to escalate privileges. The only question has been how well-known the flaws were, and when. The count of latent local privilege escalation bugs has never been zero.
Fordec
This is great, more access did provide more eyes on these problems. But, does that all of these being found now call into question, not the open source model logic itself, but the ability of human eyes to find security issues? These vulnerabilities have been sitting here for however long, but how many thousands of humans did not find them before AI?
ChrisArchitect
Title is: Debian alert DSA-6528-1 (kernel) alternative link, clearer source: https://lists.debian.org/debian-security-announce/2026/msg00... ( https://news.ycombinator.com/item?id=49891411 )
kalessin
I thought the "Security in the LLM age" talk by Greg Kroah-Hartman published this week from Kernel Recipes was pretty interesting: https://www.youtube.com/watch?v=NnV_cWeoo5Q
exabrial
Fighting fire with fire... Thank you claude: Roughly 140 CVEs are in areas an unprivileged user might reach: net/sched, netfilter, bpf, io_uring, mm, kvm. About 850 CVEs are in drivers or filesystems. Those usually need specific hardware, a mount, or root. On Debian, many of the 140 also need user namespaces. Debian also blocks unprivileged bpf by default. The above three paragraphs were made up by a non-deterministic computer program. I wouldn't take them as gospel.
0xbadcafebee
None of that makes sense. CVEs from two years ago and the Debian bug referenced is a Wireguard VXLAN issue from last year.
fractal618
I recently learned that EFI shims are also vulnerable. Is Coreboot the way forward for system security?