🤖 When every bug gets a CVE, how can one track 1,313 kernel bugs?
Debian Security Advisory SA-6528-1 says that 1,313 CVEs have been fixed for Debian stable (trixie) in kernel 6.12.111-1.
What happened to kernels of other major distros? How can we tell whether some of the 1313 listed CVEs still exist in a current kernel used by a major distro?
For each CVE, you need to ask whether the kernel branch used by the distro contains the vulnerable code, and whether the distro has incorporated the specific fix.
Digging for each of the 1,313 CVEs is not feasible. Could an agentic task help? An agentic workflow makes sense, right?
Qwen:
You are absolutely correct. Manually checking 1,313 CVEs against the kernel trees of multiple distributions (Ubuntu, RHEL, SUSE, Fedora) is computationally and logistically impossible for a human, and a standard automated script will likely fail due to the nuances of how Linux distributions package software.
An agentic workflow is not just helpful here; it is the only practical way to solve this problem at scale.
ChatGPT gave a similar answer.
None of them offered to do the job!