Tags: linux kernel*

0 bookmark(s) - Sort by: Date ↓ / Title /

  1. Simon Batt writes that Canonical is accelerating its update cycle for Ubuntu to keep pace with a massive surge in vulnerability reports. The developer is shifting from a staggered release schedule to a unified two-week patch cycle to manage the influx of Common Vulnerabilities and Exposures (CVEs) generated by large language models and automated AI agents. This trend reflects a "new normal" seen across the Linux kernel community, where automated bug discovery has significantly increased the workload for maintainers.

    - The surge in CVEs is partly due to the upstream kernel community becoming its own CVE Numbering Authority (CNA).
    - Linus Torvalds previously noted that AI assistants have made release candidates larger and sometimes unmanageable by reporting duplicate or menial bugs.
    - Some open-source communities are debating whether to ban LLM-generated content/code versus adopting it as a standard tool.
  2. Gregory Gibson writes about applying the Linux kernel's tool-generated content guidance to his vibe-coded Morse decoder app, CW Inspector. He used OpenAI Codex to build the app, then subjected it to the kernel's five transparency rules: name the tool, preserve inputs, keep the prompt trail, record exactly what the tool changed, and make the generated code prove itself. The process exposed a critical flaw — the decoder confidently produced a wrong answer (reading TTT E as SE) with zero errors, demonstrating that a clean run doesn't guarantee correctness.
    - The original algorithm treated the shortest 55% of keyed pulses as dots, which broke on dash-heavy messages; the fix looks for a large ratio between short and long pulse clusters before recording dot duration.
    - The author deliberately withheld the actual WAV file from Codex, providing only metadata and the expected message, to create an independent acceptance test rather than letting the model optimize against the exact sample it would later decode.
    - The kernel's guidance applies only when a tool generates something substantial (functions, files, fixes, translations), not for spelling corrections, autocomplete, or variable renames.
  3. The Armbian team has released version 26.5 of its Debian/Ubuntu-based distribution for ARM devices. This update focuses on kernel modernization, a redesigned desktop subsystem, and expanded hardware support across various SoC families.

    Key updates include:
    - Support for new boards such as Arduino UNO Q (QRB2210), Mekotronics R58S2, NanoPC-T6 LTS Plus, and others.
    - Integration of the Linux 7.0 kernel series with a bleeding-edge branch tracking Linux 7.1 for certain SoCs.
    - U-Boot modernization to version 2026.04 supporting various Rockchip development boards.
    - A redesigned YAML-driven desktop subsystem in armbian-config, adding support for KDE Plasma, MATE, and the i3 window manager.
    - Expanded architecture support extending Xfce, MATE, and other environments to ARMHF and RISC-V 64-bit.
    - Integration of Ubuntu 26.04 LTS (Resolute Raccoon) across the build matrix.
  4. Anthropic research scientist Nicholas Carlini demonstrated that Claude Code can discover critical security vulnerabilities in the Linux kernel, including a heap buffer overflow in the NFS driver that had remained undetected since 2003. By using a simple bash script to iterate through source files with minimal prompting, the AI identified five confirmed vulnerabilities across various components like io_uring and futex. This discovery marks a significant shift in cybersecurity, as Linux kernel maintainers report a surge in high-quality vulnerability reports from AI agents.
    Key points:
    * Claude Code discovered a 23-year-old NFS driver bug using basic automation.
    * Significant capability jump observed between older models and Opus 4.6.
    * Kernel maintainers are seeing a massive increase in daily, accurate security reports.
    * LLM agents may represent a new category of tool that combines the strengths of fuzzing and static analysis.
    * Concerns exist regarding the dual-use nature of these tools for adversaries.
  5. Nicholas Carlini, a research scientist at Anthropic, demonstrated that Claude Code can identify remotely exploitable security vulnerabilities within the Linux kernel. Most significantly, the AI discovered a heap buffer overflow in the NFS driver that had remained undetected for 23 years. By using a simple script to direct the model's attention to specific source files, Carlini was able to uncover complex bugs that require a deep understanding of intricate protocols. While the discovery highlights the growing power of large language models in cybersecurity, it also presents a new bottleneck: the massive volume of potential vulnerabilities found by AI requires significant manual effort from human researchers to validate and report.

Top of the page

First / Previous / Next / Last / Page 1 of 0 SemanticScuttle - klotz.me: tagged with "linux kernel"

About - Propulsed by SemanticScuttle