frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Several vulnerabilities have been discovered in the Linux kernel

https://lwn.net/Articles/1097401/
58•luispa•2h ago

Comments

modeless•1h ago
1,313 vulnerabilities, to be precise.
nathell•17m ago
In Heroes of Might & Magic 3, “several” means 5–9. 10–19 is “pack”, 20–49 is “lots”, 50–99 is “horde”, 100–249 is “throng”, 250–499 is “swarm”, 500–999 is “zounds…” and 1000+ is “legion”.

I suggest this post be renamed “A legion of vulnerabilities has been discovered…”

thallium205•1h ago
Pretty much any kernel bug gets a CVE by default now, right?
wjholden•57m ago
Is that all there is here? The quantifier "several" did not prepare me for the wall of CVE numbers in this list.
vdfs•17m ago
https://docs.kernel.org/process/cve.html states that because almost any kernel bug can potentially compromise system security, the CVE team acts with extreme caution and labels nearly all bug fixes with a CVE
slopinthebag•41m ago
yes because the majority are memory safety issues, and it's automatically assumed that a memory safety bug can lead to a vuln

one again illustrating the importance of encapsulating unsafe behavior. perhaps c should get a __UNSAFE { } block, where memory access is encapsulated and thus most bugs occurring outside of those blocks do not need to be marked as CVEs.

akersten•37m ago
> perhaps c should get a __UNSAFE { } block,

I think the convention for this is at the filesystem level and most programmers use the `.c` suffix to indicate it

slopinthebag•20m ago
in that case we need a block of system memory marked as unsafe so i can run these programs in it encapsulated

perhaps we could call it a sedimentchest?

seba_dos1•26m ago
Yes. It looks funny, but it's a nothing burger.
DominoTree•58m ago
I was looking earlier and the majority of these do not have a CVSS score assigned to them yet, but a lot of them that did were >7.0 (although I suppose by nature that the more impactful CVEs are going to be scored more quickly)
BobbyTables2•47m ago
Are these primarily AI-assisted findings ?

Seems like an enormous increase over 2024 and 2025.

ganelonhb•26m ago
Yes, naturally. It’s a brave new world.
tetrisgm•42m ago
That’s probably a great thing. The initial friction of AI overwhelming projects certainly sucks, but once there are better processes to deal with them it’s going to strengthen the quality of so many projects!
SchemaLoad•35m ago
Long term we will end up with software with no low hanging fruit exploits left. But right now we are in a period where low hanging fruit is everywhere and it's easier to exploit systems than ever before.
sva_•36m ago
Seems like the CVE sequence has, for the first time, reached >100000 this year (Which does not imply 100k vulns though)

Apparently by late summer this year, there were already more vulnerabilities found than in all of 2025.

SadErn•36m ago
AI is finishing the job that Snowden started. If we backfill all these holes privacy can be preserved.
imoverclocked•35m ago
Is there a way to know if a particular vanilla kernel has a particular CVE addressed? Unhelpfully, the ChangeLog-* only seems to contain sporadic references to CVEs.
crtasm•32m ago
Clicking them here lists specific kernels, is that enough to tell you?

https://security-tracker.debian.org/tracker/source-package/l...

imoverclocked•26m ago
That's useful if you run a Debian-packaged kernel.

Searching around, the best I have found so far for vanilla kernels is: https://linuxcvetracker.com

It does require a little clicking around to get all the info I want though. Time to pull out curl+awk! :)

embedding-shape•27m ago
"Several" feels a bit of an understatement, there are 1313 CVEs listed on that page!

Wonder how many of these NSA and others been sitting on, for how long and how many are still there? I guess the silver lining with the aixplosion of CVEs is that software eventually will get more secure.

SchemaLoad•19m ago
Something to keep in mind is the Linux project registered as an authority to create their own CVE numbers in 2024. Previously the majority of bugs would just be fixed without note unless there was a demonstration that it could be exploited.

Now they just give almost every bug a CVE number.

vdfs•19m ago
Any kernel bug gets a CVE even if it's not really a vulnerability or can be exploited
jaimex2•24m ago
s/discovered/fixed
userbinator•21m ago
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Remotely or locally exploitable? This is very lacking on information.

SchemaLoad•17m ago
If they were bugs of consequence you could expect each one to get it's own domain with a scary name and a logo.
adastra22•10m ago
Unfortunately no, there are a lot more that fly under the radar.
john_strinlai•15m ago
note that _any_ bugfix is assigned a cve, which makes for big numbers.

>“Due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel… Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify.”

https://docs.kernel.org/process/cve.html

"number of cves" is a useless metric, especially when it comes to the kernel.

rerdavies•5m ago
[delayed]
SAI_Peregrinus•5m ago
Tautologically every bug can legitimately be assigned a CVE, since every bug prevents some feature from working as intended. It's therefore a denial of service, which by the definition of the CVE system using CVSS means every bug is at least a 1/Low level vulnerability to CVSS v4.0.

If you're willing to stretch, missing but planned features also deny the use of said features since they haven't been added yet, and so are CVSS 1/Low vulnerabilities.

Resume-driven development for security researchers has never been easier!

drfloyd51•7m ago
Is it possible that some of these bugs were already exploited by governments? And AI might help use close of that kind of thing? (And expose other kinds of things , in a kind of AI arms race?)
jeffbee•7m ago
Linux has never, at any point in history, lacked flaws that could be exploited to escalate privileges. The only question has been how well-known the flaws were, and when. The count of latent local privilege escalation bugs has never been zero.

Pi 1.0

https://earendil.com/posts/pi-1-0/
728•sergiotapia•5h ago•249 comments

Several vulnerabilities have been discovered in the Linux kernel

https://lwn.net/Articles/1097401/
61•luispa•2h ago•31 comments

Clef: Open-weight decision models, and new RL fine-tuning platform

https://blog.cloudflare.com/clef-decision-models/
424•jasondavies•8h ago•158 comments

SvelteKit 3

https://svelte.dev/blog/sveltekit-3-is-here
110•sampsn•5h ago•40 comments

Ask HN: Who is hiring? (October 2026)

148•whoishiring•10h ago•153 comments

CSS Bed: Classless CSS themes to use as starting points in web development

https://www.cssbed.com
55•sea-gold•3h ago•11 comments

Pi Durable

https://earendil.com/posts/pi-durable/
216•paulsmith•5h ago•23 comments

Show HN: Janus – Go binary that runs GGUF models via Vulkan on AMD/Intel/Nvidia

https://github.com/Vibra-Ingenn/Janus
47•Maverick617•4h ago•5 comments

StreetComplete on iOS is now in public beta

https://github.com/streetcomplete/StreetComplete/issues/5421
520•Snowly•14h ago•127 comments

Using Opus 5.5 to discover a new eyewitness record of the dodo

https://resobscura.substack.com/p/using-opus-55-to-discover-a-new-eyewitness
59•benbreen•4h ago•6 comments

RIP, vector database

https://turbopuffer.com/blog/rip-vector-database
271•razin•9h ago•78 comments

Git 3.0's upcoming SHA-256 default will be a costly mistake

https://blog.gitbutler.com/git-3-sha-256
198•chmaynard•8h ago•213 comments

Oxygen-deprived underwater zones may not be “dead zones” but clue to early life

https://agupubs.onlinelibrary.wiley.com/doi/10.1029/2026AV002570
77•gumby•6h ago•3 comments

ArXiv's Updated Rate Limit Policy

https://blog.arxiv.org/2026/10/01/updated-rate-limit-policy/
64•50kIters•5h ago•27 comments

Aweb – Communication for AI Agents

https://aweb.ai
18•gurjeet•3h ago•12 comments

Vote on which of Hacker News' challenges for AI have been met

https://stoppels.ch/goalposts/
86•stabbles•7h ago•93 comments

Various Projects Find Hidden SDR Capabilities in ESP32 Microcontrollers

https://www.rtl-sdr.com/various-projects-independently-find-hidden-sdr-capabilities-in-esp32-micr...
164•nkw•10h ago•26 comments

Automatic Transmission – a data-privacy study of connected vehicles

https://automatictransmission.khoury.northeastern.edu/index.html
140•rafaelc•4h ago•135 comments

Cloudflare K2: serverless event streams

https://blog.cloudflare.com/cloudflare-k2-streams/
197•elffjs•11h ago•80 comments

Apple's smart home camera reportedly won't record video

https://www.theapplepost.com/2026/10/01/72882/apples-smart-home-camera-reportedly-wont-record-video/
10•mikelgan•2h ago•16 comments

Bez: Generating a browser engine from specs and tests

https://tangled.org/burrito.space/bez
86•nerdypepper•7h ago•35 comments

2026 International Utility Locate Rodeo

https://locaterodeo.net/
11•K7PJP•2h ago•0 comments

RacketCon Is Saturday

https://con.racket-lang.org/
125•spdegabrielle•10h ago•36 comments

Show HN: Open-source model routing for coding agents at Astra-level performance

79•adchurch•1d ago•22 comments

Ask HN: Who wants to be hired? (October 2026)

89•whoishiring•10h ago•272 comments

Context Language Models

https://arxiv.org/abs/2609.37725
103•emersonmacro•10h ago•26 comments

The death of web development education

https://molily.de/web-dev-education/
156•ibobev•4h ago•117 comments

How to speed up the Rust compiler in September 2026

https://nnethercote.github.io/2026/09/30/how-to-speed-up-the-rust-compiler-in-september-2026.html
230•trickypr•12h ago•117 comments

GPT-Synopsys: Frontier Intelligence to Revolutionize Chip Design

https://news.synopsys.com/2026-09-30-OpenAI-and-Synopsys-Announce-GPT-Synopsys-Frontier-Intellige...
166•giuliomagnifico•14h ago•97 comments

Butterflies use optical illusions to dodge predators

https://www.essex.ac.uk/news/2026/09/30/butterflies-use-optical-illusions-to-dodge-predators
9•gmays•2h ago•3 comments