The Point: Automated CVE filtering and continuous updates are the only practical strategy against the rising flood of kernel vulnerabilities, as manual prioritization of individual CVEs no longer scales.
Over 430 CVEs for the Linux kernel were registered within 24 hours. The surge results from clearing a multi-week review queue and increasingly AI-driven source code analyses that automatically identify defects in code.
In a matter of hours, over 430 new Common Vulnerabilities and Exposures (CVEs) for the Linux kernel entered the public database. This volume has sparked discussions in the systems administration community — not only about managing the security disclosures, but fundamentally about the feasibility of handling such backlogs.
Greg Kroah-Hartman, the leading kernel maintainer, explained that the sharp increase stems primarily from a multi-week review queue that had accumulated during conferences and vacation periods. A significant driver for the generally rising number of CVEs is the increased use of AI-driven tools and large language models (LLMs) in code analysis — already in May, Linus Torvalds warned about this development and its impact on the kernel security mailing list.
Kroah-Hartman emphasizes that the problem is not limited to the Linux kernel and that organizations in general must reconsider their update processes. His clear recommendation: manual, CVE-by-CVE patching is not practical. Instead, he advocates for complete, continuous kernel updates or automated procedures. Enterprise distributions achieve a significant reduction in review effort through automatic matching of affected files with actually compiled components — in this way they can eliminate approximately 90 percent of reported CVEs.
Regarding future developments, Kroah-Hartman expressed concern: the number of problems identified by LLMs is currently only increasing. He expects at least 18 months until the community has overcome this backlog crisis, and he advises operators to aggressively update their systems during this period in order to maintain an acceptable level of security.
Source: www.it-daily.net · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.