Posts
495
Following
100
Followers
5070
Here's a bit more up to date version of the "how many CVEs have we fixed" stats than what I showed earlier this week at @KernelRecipes as I was able to catch up on some reviews on my way home on the train.

Also cve.org just crossed the 100000 numbering barrier just now, first time that ever has happened, hopefully no scripts broke. And yes, the kernel.org CNA has CVE-2026-100000 reserved, need to find a "good" bug for that one, suggestions welcome!
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx
1
9
20
My secret kernel review tools were spotted in the back of the @KernelRecipes room
2
28
101
I can't resist keyboards in "odd" formats...
2
3
38
Some talks just write themselves, @KernelRecipes is going to be fun this year!

(not that it's not fun every year, but you get the idea...)
9
42
90
Another one of those mornings....
7
5
40
New desktop addition, a "big button" to do a kernel release. Would have come in handy earlier today when I had to do a bunch of them ...
2
20
76
My build system right now, as it's one of "those" mornings....
5
7
39
As people keep guessing what/who `gkh_clanker_t1000` is: https://lore.kernel.org/r/20260424054143.087847e1617a84df8b501313@linux-foundation.org

here it is after I cleaned up some of the horrid cable mess that had grown up around it.
5
18
64
Curiosity got the best of me, and I clicked on the links and this just looks like an OpenAI "sales funnel", which is pretty hilarious when you consider the target was open source security teams, none of which could ever fill out these types of forms without flat out lying.
4
6
31
Looks like the AI companies have finally run out of money as they are asking various open source projects to test their closed source products for them for free. What could go wrong with giving access to an unknown tool to private code repos?

If I didn't know better, I would think this is an elaborate phishing scam, or they have run out of data to scrape and need more training material.

Gotta admire their brazenness...
9
53
89
Traditional #FOSDEM lunch break, club-mate and kernel CVE assignments.
2
13
75
As seen in the Seoul Lablup office (https://www.lablup.com/) when visiting the other day right before the OSS Korea conference. Many thanks to them for the good conversations, and food and beer!
3
12
37
@jarkko Great idea, now fixed!
1
0
3
Pro tip, when sending a bug to the kernel security team, and it's reviewed and shown to not actually be a bug at all due to the report being "written" by a llm which can't actually parse C very well, don't proceed to "curse" the reviewer for pointing this out.

{sigh}
6
34
89
Yet another thing I never thought I would be doing as a kernel developer, talking about EU regulations with open source finance people...
1
9
43
My seat name tag for the EU CRA meeting today...
23
37
198
Scariest cable I have that I actually use. It's a USB-C to Thinkpad "adapter" that I bought to power a thinkpad that shipped with a giant 135W brick-of-a-power-supply. This cable does work, but has the tendency to "overload" many USB chargers, causing them to reset. Fun times, but good for traveling so I don't have to lug the brick around with me as well.
2
1
18
New year, new hardware failure, must be time for a new motherboard, any recommendations of what the "best" AMD workstation motherboard is these days?
6
1
10
New hardware showed up today, turns out Linux works just fine on it. Here's the 6.12.1 kernel running in Wayland.

Water bottle for scale.
5
10
42
In non-CVE news, here's some fun hardware I got while visiting Hong Kong. It's not the snappiest laptop I've ever used, but it holds potential!

Kernel source is all public (there's a 6.1.y and 6.6.y tree at the moment), hopefully will start working on getting it all merged upstream to make it a proper platform for others to use.
3
9
31
Show older