you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 4 hours ago (2 children)

I saw this in the CISA announcement today. I was wondering if either:

  1. the project to port the kernel to rust Or
  2. people using AI to look for vulnerabilities

Caused the huge list?

(IBM had a ton too)

  • source
  • hideshow 2 child comments
  • [–] 4 points 3 hours ago*

    It’s the latter; the kernel CVE report counts have gone through the roof in the past few years.

    No one is porting the whole kernel to rust (as part of the official project, at least).

  • source
  • parent
  • [–] 2 points 3 hours ago

    More the fact that it's Debian and they still support huge amounts of ancient stuff. There are year's old ones in the list... alas, Debian still supports kernels like 5.10LTS. And backporting fixes doesn't get easier over time.

  • source
  • parent