The Register reports that Debian’s DSA-6528-1 kernel security advisory for Debian 13 Trixie covers kernel package 6.12.111-1 and lists 1,313 CVE identifiers, a tally the article attributes largely to LLM-assisted bug hunting that has already swamped the Linux security mailing list and added to maintainer workload. It notes the kernel project became a CVE Numbering Authority in 2024 and assigns CVEs automatically after fixes reach a stable tree, so an identifier alone says little about severity or exploitability, and points to Greg Kroah-Hartman’s October 3 release of kernel 6.12.112, whose changelog runs past 27,000 lines, as evidence of the scale maintainers now handle.
Debian's latest kernel security update has 1,313 reasons to patch
The Register reports that Debian's DSA-6528-1 kernel security advisory for Debian 13 Trixie covers kernel package 6.12.111-1 and lists 1,313 CVE identifiers, a tally the article attributes largely to LLM-assisted bug hunting that has already swamped the Linux security mailing list and added to maintainer workload. It notes the kernel project became a CVE Numbering Authority in 2024 and assigns CVEs automatically after fixes reach a stable tree, so an identifier alone says little about severity or exploitability, and points to Greg Kroah-Hartman's October 3 release of kernel 6.12.112, whose changelog runs past 27,000 lines, as evidence of the scale maintainers now handle.
Source: The Register