Linux kernel team publishes 432 CVEs in two days
The Linux kernel security team published 432 CVEs across a single weekend (Sunday and Monday), overwhelming sysadmins and security professionals who must decide how to prioritise and patch them. The sudden surge has prompted concern that traditional, individualised vulnerability triage is no longer feasible, with some experts speculating that AI-assisted bug hunting is behind the flood of reports, echoing warnings Linux creator Linus Torvalds made in May about the kernel security mailing list becoming unmanageable.
Jan Schaumann, chief information security architect at Akamai, raised the alarm on the OSS-SEC mailing list, arguing it is no longer practical to prioritise individual kernel changes and that even using an LLM to triage the backlog wouldn't meaningfully help. He suggested automated, frequent fleet-wide updates as the only realistic approach, though he acknowledged this is difficult for large organisations with lengthy QA cycles and long-term support commitments. Kernel maintainer Greg Kroah-Hartman has previously noted that the kernel team assigns a CVE to any bugfix that could affect a system's confidentiality, integrity or availability, meaning many entries in this batch are minor in scope but still technically qualify as vulnerabilities.
- Linux kernel team published 432 CVEs over one weekend, alarming sysadmins.
- Experts say individually prioritising each fix is no longer feasible.
- AI-assisted bug hunting is suspected as a driver of the surge.