Conversation
Some talks just write themselves, @KernelRecipes is going to be fun this year!

(not that it's not fun every year, but you get the idea...)
8
31
69

@gregkh What does this graph mean, then? Are new releases filled with bugs or does 7.0 coincide with a new generation of scanning tools?

1
0
0

@gregkh @KernelRecipes looks like 7.0 has more vulnerabilities than 6.0 :P

1
0
0

@joshbressers @gregkh @KernelRecipes One never knows until they are found.🤷🏻‍♂️

0
0
0

@gregkh @KernelRecipes Likely the title should be “CVEs fixed per release”. A separate graph showing which versions are affected is a way better graph as it would show when a problem was introduced and when the problem was discovered and fixed.

Discovery/fix is shown in the above graph, but it does not show how long that problem was present and thus exploitable.

2
0
0
@jeroen @KernelRecipes I'm not posting all of my graphs here at the moment, you'll have to wait for the talk in a month!
1
0
2

@gregkh @KernelRecipes looking forward ;)

I think that, yes, with LLMs more are discovered and then fixed; but I wonder how many have been introduced recently too.

0
0
0
@gregkh @KernelRecipes Heh ... I have a similar plot from the 7.2 development-statistics article that I'm thinking of using...
1
3
2

@jeroen @gregkh @KernelRecipes the graph I really want is CVEs introduced per release

1
0
0
@esoterra @jeroen @KernelRecipes you have access to the same tools I do, it's easy to calculate yourself!

Hint, 5.15 is the leading "most CVEs created" kernel release for some reason...
0
1
2
@corbet @KernelRecipes Nice graph, glad ours align. Its as if some random tools got a bit better in finding bugs in the past months....
0
0
1

I saw some graphs for curl, which did not only show count but also severity. And that revealed that even though the number of CVEs had gone up overall that was mostly due to lots of very low severity issues.

0
0
0

@gregkh Clearly as this graph shows, changing version Number to 7.x increased the number of CVEs. My recommendation would be to go back to 6.x. - even when this means, Linus has to add some more toes and fingers to his feet and hands to count the number after the dot. I think that price is acceptable for a more secure kernel. We all would benefit from this (and some additional fingers might come handy for Linus' guitar pedal soldering hobby :p )
@KernelRecipes

0
0
0

@gregkh Do long term kernel releases also patch CVEs? And does this graph track those fixes?

0
0
0