Conversation

@gregkh Hi Greg, do you have any chart/slide to share showing Linux kernel CVEs/year or something illustrating the 2026 "explosion" ? Could fit well in a talk I will do soon. Just asking if you have something done already to share.

1
0
1

@janne @gregkh ah yes, now I even recall having seen that. Thanks!

1
0
0
@bagder @janne I can give you raw numbers if you want as well, so you can use it in your own graphing tools, I'll email them to you...
2
0
3

@bagder @gregkh @janne

Without context one might say that Linux is not very secure πŸ˜‘

0
0
0

@benbe @gregkh @janne the kernel is 200x the amount of code compared to curl but not 200x the number of CVEs...

0
0
0

@urixturing @gregkh @janne curl has more modest numbers but the same trend

0
0
0

@bagder @gregkh @janne This red color looks dangerous. Isnβ€˜t it good they are found?

*ducks*

1
0
0

@icing @gregkh @janne isn't that the color of love? 😁

1
0
0

@bagder @gregkh @janne I admit, I have not recognized the H1 love letters as what they are. This changes everything!😍

0
0
1
@bagder @janne Hey, "red" is bad, but in this case, it should be "good" in that we are fixing lots of old debt here. It's not like we are adding more buggy code, as the "where was the CVE introduced" numbers show.
But it's your graph, you pick whatever color you want :)
2
0
3

@gregkh @bagder @janne
Don't the "introduction" numbers show pre-git Linux as second place? (1st place I think introduced NTFS and more)

1
0
0

@gregkh @janne in this case I use red for "hey look this is the number that stands out compared to the rest". There's some blabbing associated with it too that should clarify how it can be viewed and interpreted.

0
0
0
@libewa @bagder @janne For CVEs, no, the numbers do not show that at all, it's 5.15 that is the "highlight". But note we didn't really start tracking CVEs until 2024, so historical data is going to be hard to compare properly.
0
0
0