โŒ

Normal view

Debian's latest kernel security update has 1,313 reasons to patch

5 October 2026 at 15:35
The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers. The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later. The Debian security tracker links to descriptions of the individual issues. We have not examined every entry. If we had, this article would not appear until after Debian 13.8 (which is likely to appear later in October), or possibly at some point in 2027. Several checked at random also affect older kernel versions, so the list should not be read as a tally of bugs introduced in 6.12.111. The Linux kernel project became a CVE Numbering Authority (CNA) in February 2024. Back in February this year, kernel maintainer Greg Kroah-Hartman described the Linux CVE assignment process in some detail. He said kernel development averages around nine changes an hour, with a feed of known bug fixes averaging about 30 changes a day providing the basis for the CNA team's review. The kernel team's policy is to assign CVEs automatically after fixes have reached a stable kernel tree. It takes a deliberately cautious approach because the security implications of a bug may not be apparent when it is fixed. A CVE identifier alone therefore says little about severity or exploitability. We strongly suspect that this number of CVEs is due to LLM bots doing the bug hunting, and quite possibly doing the bug fixing as well. Linux is not an anti-AI project, and neither is Debian. AI-assisted bug hunting is already swamping the Linux security mailing list, as The Register reported in May. Kroah-Hartman released kernel 6.12.112 on October 3. Its detailed changelog runs to more than 27,000 lines. With both the rates of change and the sizes of the changes getting so large, it is hard to deny that LLM bot assistance must be very useful to the hard-pressed maintainers. Whether coding bots constitute a net benefit to the projects, to software, or to humanity as a whole remains at best an open question. ยฎ

CVE flood pushes Ubuntu onto weekly kernel release cycle

24 September 2026 at 16:33
Canonical is speeding up Ubuntu kernel releases to one a week as AI-assisted bug hunting helps bury defenders under an ever-growing pile of CVEs. The Ubuntu maker is overhauling how it ships kernel Stable Release Updates (SRUs), replacing its current four-week regular and two-week security cycles with overlapping two-week cycles that will push a kernel release every week. Canonical says the change is needed because the number of reported vulnerabilities has exploded, with AI deserving some of the credit โ€“ or blame, depending on which side of the patch queue you're sitting. "Large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time-intensive process into a highly automated engine," Canonical said on Wednesday. AI isn't solely responsible for the CVE avalanche. The upstream Linux kernel community became a CVE Numbering Authority in 2024 and began assigning identifiers to thousands of bugs on the basis that almost any kernel flaw affecting a running system could have security implications. Put the two together, and Linux vendors have far more CVEs to deal with. Canonical says the resulting backlog requires faster releases to shrink the window between vulnerabilities becoming public and patched kernels reaching users. Under the new system, each SRU cycle lasts two weeks, but a new one starts every week. The first week is spent integrating patches, preparing and building kernel packages, and carrying out basic checks to make sure nothing catches fire. By the end of that stage, release candidates are published to Ubuntu's -proposed pocket. Week two is reserved for the heavier stuff, including hardware certification, distro integration, and regression testing. Once that's done, the kernel is released. Because the next cycle starts while that testing is under way, Canonical can publish another kernel the following week. For admins who consider even that too leisurely, there's a faster route. Organizations particularly sensitive to patching delays can take release candidates from the -proposed pocket after the first week and run their own acceptance tests. Canonical makes the trade-off clear: those users get access to fixes sooner, but before the company has finished its extensive certification testing. That can make kernel CVE fixes available within a week, provided customers are willing to perform some of the testing themselves. Canonical also wants to leave customers less exposed between disclosure and patch availability. It aims to provide safe workarounds where possible, or recommend general hardening measures where none exist, putting systems into what it calls a "defensible, safer state" within 24 to 48 hours of public disclosure. Those measures are not intended to replace patching, merely to give admins something better than crossing their fingers while a fix makes its way through the release process. The end result is a considerably busier kernel release schedule, although perhaps that's inevitable when machines are increasingly being enlisted to find bugs faster than humans can patch them. AI was supposed to make everyone's jobs easier. Ubuntu's kernel team may want a word. ยฎ

Omarchy distro gains serious backing

27 August 2026 at 17:07
The controversial Omarchy distro is attracting both criticism and fans โ€“ and financial support, too. Omarchy is an opinionated respin of Arch Linux and a pet project of Ruby on Rails creator David Heinemeier Hansson, better known as DHH. Although the first release was as recent as June last year, this week sees the release of Omarchy 4.0.1 โ€“ a security fix for the mid-August Omarchy 4 โ€œQuattroโ€. Although it started out just over a year ago, Omarchy now has a sibling project Omakub, which is based on Ubuntu, and an organization behind it called Omacom. A week ago, DHH announced the launch of the Omacom Foundation with $8 million. Its founding patrons include figures behind Shopify, Stripe, Dell, Block, Cloudflare, Sesame, and 37signals - closely followed by people behind Dropbox and OpenClaw, taking the total to $10 million. The project, like the man behind it, is controversial. But that means attention, and an โ€œopinionated distroโ€ gets opinionated reviews. Some of the criticism is strong stuff: for instance, Merchants of Insecurity, whose top line is: โ€œFirst, a PSA: Do NOT use Omarchy if you care about security of your machine even a little bit.โ€ Author โ€œOne Happy Fellowโ€ is not the first: last year, a member of Framework's community forums posted Omarchy is not a secure distribution and should be taken off the Linux installation options. Others like it or give it a guarded thumbs up while saying itโ€™s not for them. There really is no such thing as bad publicity. As P. T. Barnum put it: "Say anything you like about me, but spell my name right." DHH is no stranger to controversy. We suspect he doesnโ€™t mind at all. The Register reported in late 2025 that Framework, known for its repairable laptops, was sponsoring Omarchy and Hyprland, and in turn, multiple people criticized Framework for sponsoring such controversial projects. That piece linked to some of the criticism of DHH, but he has been attracting criticism since at least 2014. We tried it, and it does work. It has a unique UI based on the Hyprland tiling compositor and a panel and menus provided in the new release by Quickshell. This is heavily keyboard-driven, but ignores almost all existing keyboard shortcuts and UI conventions from other OSes. There are no title bars, let alone close buttons or anything like that. No middle-click or right-click app menus. The jaded take of the Reg FOSS desk, who is a big fan and advocate of keyboard-driven UIs, is that such things usually reflect ignorance of existing user interface standards. We found it a bit clunky. We had to install an additional tool, hypermon, in order to be able to make our testbed machineโ€™s second display useful. You canโ€™t use established pacman commands to update it โ€“ you must use the custom omarchy update script, and when trying that in a VM, we hit a known bug. On hardware, it worked fine. Itโ€™s Arch, extensively preconfigured. Lots of apps are preinstalled, and the selection is surprising and not typical of a FOSS product. The selection includes Discord and WhatsApp for communications, Docker, Obsidian for note-taking, Neovim as an editor, and OBS Studio for streaming. There are optional extras for using speech, automatic dictation via Voxtype, and other unusual features. Thereโ€™s a terminal-based music player, cliamp. (We like the name of that one, and may keep it around.) There are, of course, options to add AI tools โ€“ one of the startup messages invites you to configure your preferred plastic pal whoโ€™s fun to be with LLM bot. Itโ€™s pretty big. A default install (not that there is any other kind) took 14 GB of disk space after the first update. It did install in a VM with a 16 GB virtual disk, but there wasnโ€™t enough disk space to update the OS. It uses about 1.5 GB of memory at idle. Itโ€™s not lightweight, but then, Omarchy definitely comes with batteries included, as well as (to quote a friendโ€™s old email signature) โ€œbells and whistles, plus a couple of gongs. Donโ€™t forget the horns, the custard pies and the water-powered whirling knives.โ€ If you donโ€™t know your way around existing environments or distros, want something fashionable and snazzy looking, and are willing and happy to jump in and learn, then this is an interesting new option. You may not agree with the politics and views behind it, but you must be able to either tolerate them โ€“ or ignore them. It works, itโ€™s quite fast, it looks striking, and it does the job. If you just want something clean, fast, pretty, and with tiling by default, personally, weโ€™d suggest Pop!_OS instead. ยฎ

โŒ