So to synthesize a ton of threads... 1300+ CVEs were issued, but no one has verified that all of those are *actually* security issues or are just bugs, thus rendering the CVE system meaningless?
Right?
So to synthesize a ton of threads... 1300+ CVEs were issued, but no one has verified that all of those are *actually* security issues or are just bugs, thus rendering the CVE system meaningless?
Right?
@cthos at that volume, are these slop-sourced?
@zkat It looks like it's a combination of "flood of slop sourced bug reports" and "the kernel maintainers submit basically everything as a CVE", with this post and the attached threads being the source of that info. But yeah, TIL the kernel just CVEs everything.
@zkat But like....yeah, I'm extremely wary about updating _anything_ right now because who knows if more slop is making more and worse vulns?
@cthos @zkat Seems to suggest they might not be the most responsible #slop users that there is no response here: https://lore.kernel.org/lkml/e12330b9-c29e-45ca-9375-9e3d13426d85@horse64.org/T/
Feel free to express your concerns as a response to those emails, in a thoughtful calm manner of course. If more people do, there's more likely going to be a response from the #linux #kernel team.
#noai #llm #ensloppification #noslop #sloppening #freesoftware #foss #floss #opensource #ai
@cthos it is a god damn mess for sure. None of the kernel patch + cve pipeline was designed to handle this sort of input volume.
This is effectively a denial of service attack on the cve system.