@gregkh What does this graph mean, then? Are new releases filled with bugs or does 7.0 coincide with a new generation of scanning tools?
@gregkh @KernelRecipes looks like 7.0 has more vulnerabilities than 6.0 :P
@joshbressers @gregkh @KernelRecipes One never knows until they are found.🤷🏻♂️
@gregkh @KernelRecipes Likely the title should be “CVEs fixed per release”. A separate graph showing which versions are affected is a way better graph as it would show when a problem was introduced and when the problem was discovered and fixed.
Discovery/fix is shown in the above graph, but it does not show how long that problem was present and thus exploitable.
@gregkh @KernelRecipes looking forward ;)
I think that, yes, with LLMs more are discovered and then fixed; but I wonder how many have been introduced recently too.
@jeroen @gregkh @KernelRecipes the graph I really want is CVEs introduced per release
I saw some graphs for curl, which did not only show count but also severity. And that revealed that even though the number of CVEs had gone up overall that was mostly due to lots of very low severity issues.
@gregkh Clearly as this graph shows, changing version Number to 7.x increased the number of CVEs. My recommendation would be to go back to 6.x. - even when this means, Linus has to add some more toes and fingers to his feet and hands to count the number after the dot. I think that price is acceptable for a more secure kernel. We all would benefit from this (and some additional fingers might come handy for Linus' guitar pedal soldering hobby :p )
@KernelRecipes
@gregkh Do long term kernel releases also patch CVEs? And does this graph track those fixes?