Three prevalent themes in the discussion
- Kernel CVE assignment inflates numbers – Many commenters note that the Linux kernel team now assigns a CVE to almost every bugfix, regardless of exploitability.
- “Any kernel bug gets a CVE even if it's not really a vulnerability or can be exploited” – vdfs
- “Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable… Because of this, the CVE assignment team are overly cautious and assign CVE numbers to any bugfix that they identify.” – john_strinlai (citing kernel docs)
-
“Something to keep in mind is the Linux project registered as an authority to create their own CVE numbers in 2024… Now they just give almost every bug a CVE number.” – SchemaLoad
-
CVE overload reduces usefulness and creates patch fatigue – Participants argue that the sheer volume (and low‑severity scores) makes CVEs noisy, hard to triage, and leads to unnecessary updates.
- “There is exactly one CVE in the entire list that is high severity… You can skip the Xanax this week.” – sippingabonedry
- “Severity on cve is a crapshoot most of the time… ALWAYS ignore any attempt that groups such as NIST/NVD that purport to assign things like CVSS scores to a vulnerability.” – john_strinlai
-
“If your system goes down to update a kernel then you have a major issue already… We need to switchover to microkernel operating systems ASAP or our entire computing infrastructure becomes a liability.” – hn_submit (reflecting admin burden)
-
AI/LLMs are reshaping vulnerability discovery and code quality – The thread repeatedly ties the surge in reported issues to AI‑assisted finding (and generation) of code, seeing both opportunity and risk.
- “Are these primarily AI‑assisted findings ? Seems like an enormous increase over 2024 and 2025.” – BobbyTables2
- “Long term we will end up with software with no low hanging fruit exploits left. But right now we are in a period where low hanging fruit is everywhere…” – SchemaLoad
- “AI makes language choice a lot less important here; it's incredibly good at finding the bugs.” – 0c3ca83
- “We didn’t see 1000+ easily exploitable RCEs.” – exabrial (AI‑generated estimate)
- “If we did secure software across the board with AI, there'd likely be a resurgence of calls for mandatory backdoors.” – rockskon (security‑policy implication)