Debian's latest kernel security update, DSA-6528-1, lists 1,313 CVE identifiers for kernel package 6.12.111-1 on Debian 13 (Trixie). The advisory, published September 29, arrived after Debian 13.7 shipped on September 12 and upstream kernel 6.12.111 landed nine days later. The Register notes that the list should not be read as a tally of new bugs: several entries randomly checked also affect older kernel versions.

Part of the reason for the large count is the Linux kernel project's CVE assignment process. The kernel became a CVE Numbering Authority in February 2024. Maintainer Greg Kroah-Hartman has described a workflow in which kernel development averages about nine changes an hour and the CNA team reviews a feed of roughly 30 known bug fixes per day. CVEs are assigned automatically after fixes reach a stable tree, and the team deliberately errs on the side of caution because a bug's security impact may not be clear at fix time. As a result, a CVE identifier alone says little about severity or exploitability.

The Register speculates that AI-assisted bug hunting is behind the surge in CVE numbers, and that LLM bots may be doing some of the fixing as well. AI-assisted hunting is already overwhelming the Linux security mailing list, and kernel 6.12.112, released October 3, carries a changelog of more than 27,000 lines. Whether such bots are a net benefit to maintainers, projects, or humanity remains an open question.