[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-linux-kernel-cve-ai-overwhelmed":3,"news-related-b1645fba-d364-47e6-97da-06868f98d987":38},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"b1645fba-d364-47e6-97da-06868f98d987","Linux 内核 7.x 每版近 2000 个 CVE:AI 帮倒忙,维护者不堪重负","Linux 内核 CVE 数量从 6.x 的约 500 飙到 7.x 系列接近 2000,主因是 LLM 自动扫描提交了大量低优先级的“AI 发现”,维护者 Jakub Kicinski 直言“完全顶不住”。","## 背景:从 500 到 2000,CVE 翻了三倍多\n\nGreg Kroah-Hartman 在为 9 月 21-23 日巴黎 Kernel Recipes 2026 演讲准备的幻灯片里,把一组数字摆在台面上:整个 Linux 6.x 时代每个稳定版修复的 CVE 大约在 500 个上下;Linux 7.0 把这个数字推过 1000,7.2 已经超过 1500,按目前的曲线走,即将在 10 月底前后释出的 Linux 7.3 会突破 2000。内核源码在这 35 年间累积到 4000 万行以上的体量,而这一波增长几乎完全来自外部 LLM 和 AI 静态分析工具的自动扫描,而不是内核真的变脆弱了。\n\n## 出处与口径\n\n数据来源是 Tom's Hardware 9 月 1 日的报道,转引自 Kroah-Hartman 的幻灯片,以及 Linux 7.3 网络子系统 pull request 里 Jakub Kicinski 的统计。这一说法与 Solidot 在 9 月 3 日的中文简报相互印证:同一组数字、同一批维护者发言。\n\n## 维护者的处境:三分之一到一半是噪声\n\nKicinski 在 Linux 7.3 网络 pull request 里给了一个非常硬的判断:这一轮 648 个 net-next 补丁里,他估计三分之一到一半是 AI 驱动的低优先级补丁、清理或“修辞式澄清”。他直接写下 “We are completely overwhelmed”。这些补丁的源头往往是冷门 ISA\u002FPCMCIA 时代的旧驱动、AI 静态分析跑出来的低危报告,甚至还有模型幻觉出来的误报;内核维护者有义务去核,这是 35 年来累积的协作契约,绕不开。\n\n更麻烦的是,Linux CVE 今年的条目已经明确把 AI 辅助静态分析写进了“发现者”字段,Intel Product Security 在随后的人工复核中确认了一部分;问题是绝大多数 AI 提交的是低危、边界情况,真正可被利用的比例很小,但每一份都要花人去读。\n\n## 旧代码被当成“弃疗对象”砍掉\n\nAI 工具的低成本扫荡让一些老驱动突然“显形”,维护者开始反过来砍代码,而不是继续修。今年 4 月 Andrew Lunn 提议删除约 28000 行老旧 ISA\u002FPCMCIA 网络代码;Linux 7.3 真的移除了 SGI、IBM 的旧驱动,FreeVxFS 文件系统也因为“主要被 AI 扫描工具拿来喂报告”而被摘掉。换句话说,维护者面对的不是代码风险,而是代码本身的维护成本被 AI 重新点亮,这条平衡线已经在移动。\n\n## 内核社区的反应:不是反 AI,是反“未经验证的 AI”\n\nKroah-Hartman 自己就成功用过本地 AI 辅助工具抓到真实 bug,他反对的不是 AI 本身,而是没经过人验证就丢到邮件列表的 AI 报告。他已经把 LLM 生成的补丁挡在 staging 子系统之外,除非能证明是真正的安全修复;最新的内核文档也明确警告,未人工核验的 AI 报告是在浪费维护者时间。\n\n与此同时,内核团队选择“用 AI 打 AI”:已经拿到多个前沿模型权限用来做补丁复核、过滤幻觉产物,后续还考虑把更多例行行政类事务交给 LLM。\n\n## 行业含义:LLM 时代的开源维护成本\n\n这件事对其他大型开源项目有直接借鉴意义:LLM 大幅压低了“找 bug”的边际成本,但把成本转嫁到了人工复核上;没有反向加速机制的上游项目,迟早会撞上 Kicinski 描述的那种“完全顶不住”。对 LLM 提供方来说,这意味着要内建类似证据链、可信度评分的输出格式,而不是只给一段看似合理的报告。\n\n对关心 Linux 7.3 进展的人来说,Kroah-Hartman 会在 9 月底巴黎把更完整的数据带出来;在那之前,Linux 7.3-rc1 已经在 8 月 30 日发布,合并窗口关闭,正式版预计 10 月底释出——而 2000 这个数字,大概率会被刷新。","https:\u002F\u002Fwww.tomshardware.com\u002Fsoftware\u002Flinux\u002Flinux-kernel-nears-2-000-cves-per-release-as-ai-bug-hunters-scour-40-million-lines-of-code-maintainers-say-they-are-completely-overwhelmed","2ea3b602-f810-4167-b1ea-b56c5de103f8",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"40269b40-7942-4650-9672-ed2e6524d37a","ai-technology",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"e82b2d09-81b2-43d1-977e-e018443b3c14","coding-agent",{"id":19,"name":20,"slug":20,"description":14,"color":14},"01598627-1ea6-4b27-a5d8-874971571a71","llm",{"id":22,"name":23,"slug":23,"description":14,"color":14},"b9bd9039-fcdb-41a8-b85b-fc1587def2b9","open-source",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"a86c1c04-1af9-475f-9d6c-18c43f7502fe","en","Linux kernel 7.x nears 2,000 CVEs per release: AI helps the wrong way, maintainers overwhelmed","Linux kernel CVE counts jumped from about 500 per release in the 6.x era to nearly 2,000 in the 7.x series. The main driver is LLM-assisted scanners dumping a flood of low-priority “AI findings,” and maintainer Jakub Kicinski openly says they are “completely overwhelmed.”","## Background: From 500 to 2,000, CVEs more than tripled\n\nGreg Kroah-Hartman put a single set of numbers on a slide he is preparing for Kernel Recipes 2026 in Paris on September 21–23. Through the Linux 6.x era, each stable release shipped with roughly 500 CVE fixes; Linux 7.0 pushed that past 1,000, Linux 7.2 already exceeds 1,500, and on the current curve, Linux 7.3 — due late October — will cross 2,000. The kernel source has grown to over 40 million lines over 35 years, but almost the entire spike is coming from external LLM and AI static-analysis tooling auto-scanning the tree, not from the kernel itself becoming more fragile.\n\n## Sources and method\n\nThe numbers come from a Tom's Hardware piece on September 1, citing Kroah-Hartman's slides plus the statistics Jakub Kicinski wrote into the Linux 7.3 networking pull request. Solidot's Chinese summary on September 3 lines up: same figures, same maintainer quotes.\n\n## Maintainers' situation: one third to one half is noise\n\nKicinski's verdict in the 7.3 networking pull request is unusually blunt: out of 648 net-next patches in this cycle, he estimates one third to one half are AI-driven low-priority patches, cleanups, or “rhetorical clarifications.” He writes, flat out, “We are completely overwhelmed.” Most of those patches originate from obscure ISA\u002FPCMCIA-era drivers, low-severity findings from AI static analysis, and outright false positives from model hallucinations. Maintainers are contractually obligated to triage them — that obligation is built into 35 years of upstream workflow.\n\nWorse, this year's Linux CVE entries already explicitly credit AI-assisted static analysis under “discoverer,” with Intel Product Security confirming some of them after manual follow-up. The problem is that almost everything AI submits is low-severity or edge-case, with very little actual exploitability, but every single item still costs a human reviewer.\n\n## Old code is being cut as “abandonware”\n\nCheap AI sweeps are making old drivers suddenly “visible,” and maintainers are responding by deleting code rather than fixing it. In April, Andrew Lunn proposed removing about 28,000 lines of legacy ISA\u002FPCMCIA networking code; Linux 7.3 actually deletes the old SGI and IBM drivers, and the FreeVxFS filesystem was also dropped after its maintainer said the decades-old compatibility layer had become “mainly fodder for AI scanners.” The cost maintainers are responding to is not a code defect — it is the maintenance load that AI has just re-lit, and that line is moving.\n\n## The kernel community's response: not anti-AI, anti “unverified AI”\n\nKroah-Hartman has himself used local AI-assisted tools to catch real bugs. What he pushes back on is unverified AI output dumped onto the mailing list. He has barred LLM-generated patches from the staging subsystem except for legitimate security fixes, and the latest kernel documentation explicitly warns that unverified AI reports waste maintainer time.\n\nAt the same time, the kernel team is choosing to “fight AI with AI”: they have secured access to multiple frontier models to help review patches and filter hallucinations, and are considering moving more routine administrative work onto LLMs in future cycles.\n\n## Industry takeaway: maintenance cost in the LLM era\n\nThis is a useful warning for other large open-source projects. LLMs have dramatically cut the marginal cost of “finding bugs” and transferred that cost to human review. Any project without a matching acceleration loop upstream is eventually going to hit the same wall Kicinski describes. For LLM providers, that means building evidence chains and credibility scoring into output formats, not just emitting a plausible paragraph.\n\nFor anyone tracking Linux 7.3: Kroah-Hartman will bring fuller data to Paris in late September; in the meantime, Linux 7.3-rc1 shipped August 30 with the merge window closed, and the stable release is expected in late October. The 2,000 figure, most likely, will be revised upward.","linux-kernel-cve-ai-overwhelmed","2026-09-04T00:00:00Z","2026-09-04T07:07:29.719789Z","2026-09-04T07:07:29.719800Z",true,"agent",33,{"items":39},[40,45,50,55,60,65],{"id":41,"title":42,"news_slug":43,"published_at":44},"63c30bcd-3ffc-47c5-bd74-c2a9ed8f7c94","DeepSeek Harness 预览版开源:Agent 被拆成可插拔的插件栈,模型只负责想、Harness 负责做事","deepseek-harness-plugin-stack","2026-09-05T06:00:00+00:00",{"id":46,"title":47,"news_slug":48,"published_at":49},"c70131ba-e6b2-466a-ab36-65fad341f006","别让语音助手念出美元符号:NAVER 对齐 LLM 生成可朗读文本","tts-friendly-llm-alignment-fast","2026-09-02T23:40:00+00:00",{"id":51,"title":52,"news_slug":53,"published_at":54},"4a89fe5a-8703-49e5-b083-079cbda0fa2a","蒸馏也有副作用:中间训练期上KD,推理上涨、事实记忆反而变慢","switch-distillation-midtraining-kd","2026-09-02T17:10:00+00:00",{"id":56,"title":57,"news_slug":58,"published_at":59},"21a91da5-c5fa-45e2-b01f-a7950331cf44","S3 把 DuckDB 团队收走了:DuckLabs 加盟 AWS,MIT 开源照旧","aws-buys-ducklabs-duckdb-open-source","2026-08-30T06:00:00+00:00",{"id":61,"title":62,"news_slug":63,"published_at":64},"f9cf9f03-6aca-4d29-94d3-5c6acfeaf435","匿名模型 OX Alpha 短暂登顶 OpenRouter 编码榜:研究者推测底座指向智谱 GLM-5.x","ox-alpha-stealth-openrouter-glm-5-zhipu","2026-08-24T03:00:00+00:00",{"id":66,"title":67,"news_slug":68,"published_at":69},"7ba15299-8bee-4039-8bc7-dbb58754b562","SWE-bench Science:最强 Claude Code 修科学代码也不及格,四类失败模式被拆解","swe-bench-science-benchmark","2026-08-21T13:00:00+00:00"]