
The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers. The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later. The Debian security tracker links to descriptions of the individual issues. We have not examined every entry. If we had, this article would not appear until after Debian 13.8 (which is likely to appear later in October), or possibly at some point in 2027. Several checked at random also affect older kernel versions, so the list should not be read as a tally of bugs introduced in 6.12.111. The Linux kernel project became a CVE Numbering Authority (CNA) in February 2024. Back in February this year, kernel maintainer Greg Kroah-Hartman described the Linux CVE assignment process in some detail. He said kernel development averages around nine changes an hour, with a feed of known bug fixes averaging about 30 changes a day providing the basis for the CNA team's review. The kernel team's policy is to assign CVEs automatically after fixes have reached a stable kernel tree. It takes a deliberately cautious approach because the security implications of a bug may not be apparent when it is fixed. A CVE identifier alone therefore says little about severity or exploitability. We strongly suspect that this number of CVEs is due to LLM bots doing the bug hunting, and quite possibly doing the bug fixing as well. Linux is not an anti-AI project, and neither is Debian. AI-assisted bug hunting is already swamping the Linux security mailing list, as The Register reported in May. Kroah-Hartman released kernel 6.12.112 on October 3. Its detailed changelog runs to more than 27,000 lines. With both the rates of change and the sizes of the changes getting so large, it is hard to deny that LLM bot assistance must be very useful to the hard-pressed maintainers. Whether coding bots constitute a net benefit to the projects, to software, or to humanity as a whole remains at best an open question. (R)