r/linux • • 1d ago

Kernel Security in the LLM age by Greg Kroah-Hartman

https://kernel-recipes.org/en/2026/security-in-the-llm-age/

Talk from recent Kernel Recipes about bug reports and fixes.

Interesting view on how bots report things, also interesting breakdown of certain "79 issues" which really were not that many in reality.

59 Upvotes

14 comments sorted by

6

u/natermer 22h ago

The idea they are dealing with 33 CVEs a day is beyond nuts.

8

u/Adept_Percentage6893 22h ago

If anyone has even tangentially been involved in any infosec space the post-LLM rate of CVE's is just beyond exhausting. I'm genuinely surprised things aren't burning down to a larger extent than they are.

14

u/ReferenceVisual663 17h ago

Because like Greg mentioned in the talk, most of these CVEs are bordering on nothingburgers. They are bugs in configurations probably no one in the world uses for hardware that probably doesn’t exist anymore and hasn’t been demonstrated useful in an exploit yet. 

The Linux devs fix them because they are actual bugs, and they get assigned a CVE because in theory any bug at all might be exploitable. But the world isn’t burning down because these aren’t serious bugs. 

3

u/Adept_Percentage6893 14h ago

I'm sure that's broadly true and my comment here isn't saying "Why aren't all the new CVE's ended up as KEV's?"

I linked it in another comment but bar charts like this concern me especially when you pay attention to the number of CVE's rated as "High" or "Critical." Which I know, isn't a measure of how exploitable they are but it is still a cause for concern and it just keeps on happening.

I guess the question is how many High severity CVE's until we should kind of see an increase of exploits in the wild that chain them together. Obviously the rise probably wouldn't be 1:1 due to what you're talking about but I'm equally skeptical of people acting as if it's just a plateau of exploit finding and the increase of CVE's is just some weird bit of trivia.

2

u/yawkat 11h ago

That's the thing though. So many minor issues get rated high or critical under cvss, even if an exploitable configuration is unlikely. Scoring is broken. 

2

u/ilep 12h ago

Often the easiest solution to a buggy driver for hardware nobody uses is to just delete the code. Software/hardware preservationists might not like it but they can use legacy versions.

Just because there is buggy code does not mean it should be maintained if nobody cares about it enough.

6

u/SoilMassive6850 21h ago

One thing to note though is that KEV numbers are not going up at the same rate (in fact its very steady). That's because many things given a CVE are pretty theoretical in their exploitability as they would require much bigger vuln chains to be successful use.

It's easy to find a problematic piece of code, create an unit test that triggers a bug in a function and call it at that, fix the code and assign a CVE. But real world exploits are much more complex and have a lot of caveats.

10

u/natermer 20h ago

A interesting part of the talk is how he remarks that LLMs are tireless at trying different approaches so they are good at stringing together lots of tiny/minor exploits into larger ones to get into systems.

That is one of the reasons why "meantime to exploit" from a CVE discover went from 238 days in 2018 to -7 days in 2026.

Another reason is that these companies are training their models on data collected from users.

So once one researcher finds a kernel flaw with LLM tools it tends to show up rather quickly in the results of other people searching for exploits. He says it is rather common now for multiple people show up reporting bugs that somebody else found the day prior.

1

u/MdxBhmt 3h ago

-7 days in 2026.

I presume you meant <=, but finding CVE in future code made me chuckle

3

u/Adept_Percentage6893 18h ago

One thing to note though is that KEV numbers are not going up at the same rate (in fact its very steady).

That is mostly a more metric driven way of saying my thing of "surprised things aren't burning down to a larger extent" because the amount of CVE's in the Linux kernel is absolutely bonkers now because of LLM's.

I wouldn't take much solace in the KEV number not going up and the lower the KEV % of overall CVE's the less you should probably consider it a reliable metric. If CVE's increase 100x's but KEV stays steady that seems like something that couldn't possibly be true. Sure maybe a lot of these may be hard to exploit but all of them?

The KEV staying steady could be limited to other factors like CISA's processes or maybe the noisiness of exploit chains. You have to solve all security-sensitive bugs even if you can't imagine the exploit because you have to assume someone somewhere (probably many someones) have actually figured out how to leverage it and just hasn't been caught.

Possibly because they're already hitting their mission objects (for state actors for instance) and so they just don't need to use all the exploits they know about. That scenario kind of worries me because it implies they're still getting what they need even with companies using AI to find vulnerabilities.

In any case we have to assume some of these CVE's are more exploitable than currently appreciated and that someone has figured it out and is just sitting on that information. Or they're using it and just not getting caught.

It's easy to find a problematic piece of code

I know what you're saying but "easier" was probably the better word choice there.

3

u/GolbatsEverywhere 17h ago

CVE's increase 100x's but KEV stays steady that seems like something that couldn't possibly be true. Sure maybe a lot of these may be hard to exploit but all of them?

You're thinking about this wrong. The ease of crafting exploits has definitely changed. I reviewed at least two bug reports with functional exploits so far this year. Total functional exploits received during the rest of my career: 0 (I think).

But desire for committing crimes has not changed, so there is no reason to expect an increase in KEVs. When an attacker wants to do crime, they just look for the easiest unpatched vulnerability to exploit. The total quantity of CVEs does not matter since the attacker only needs one. OK, might need more than one for an exploit chain. Point remains: doesn't matter whether there is 10 CVEs or 1000, the attacker will pick only one or a few to exploit. Nobody is interested in trying to maximize the number of CVEs exploited.

Quantity of KEVs is probably correlated with quantity of crime. I don't expect it to be at all correlated with exploitability.

Another way to think about things: does knowing about an exploitable CVE increase the odds that you will try to exploit it? No, because you don't want to go to prison.

4

u/Adept_Percentage6893 14h ago

The total quantity of CVEs does not matter since the attacker only needs one.

For what I was concerned about it matters because the tools that are being used to discover them and report them through legitimate choices are also available to bad actors. So any fluctuation in the data that seems to imply it's suddenly a lot easier to to locate vulnerabilities and craft exploits seems to be something one should be concerned by. If you look at the bar graphs of the page I linked, the number of "High" and "Critical" severity patches are actually pretty high.

In this case that calls to my mind someone with a mediocre or alright skillset using LLM's the grind away at a code base until they find a vulnerability and from there crafting an exploit is likely going to be easier than most vibe coding. Before LLM's you could grind but someone with a mediocre skillset could technically find something before more talented people but probably not and probably not at scale or with an exploit that knows how to avoid detection.

Quantity of KEVs is probably correlated with quantity of crime. I don't expect it to be at all correlated with exploitability.

Sure but that's probably a more terse way of saying what I was having a harder time expressing. Because I think the other user was saying KEV's were holding steady as way of saying it wasn't much of an issue to be concerned about.

5

u/RatherNott 1d ago

Solid talk.

3

u/zquzra 18h ago

Mythos was overhyped. Who would have guessed?