YYaaa News

Linux Kernel drops 440 CVEs in 24 hours | largest single-batch disclosure since becoming a CNA

TL;DR

The Linux Kernel team disclosed 431 CVEs on July 19 and 9 more on July 20 — 440 vulnerability advisories in 24 hours. Most were already fixed and merged to stable before disclosure. It's the largest single-day CVE batch since the Kernel team became a CNA in 2024.

The Linux Kernel team disclosed 440 CVE advisories in 24 hours431 CVEs on July 19 in a single batch, and 9 more on July 20. It's the largest single-day disclosure since the Kernel team became a CNA (CVE Numbering Authority) in 2024.

What's interesting is most of these were already fixed and merged to stable before disclosure — advisory ships with the patch already in place. The Kernel team didn't tag CVSS scores individually, because at this batch size, per-CVE scoring costs more human hours than the CVE advisories themselves generate value.

Context: after the Kernel team obtained CNA status in February 2024, it changed disclosure policy — any bug fix merged into a stable kernel gets a CVE ID, no longer distinguishing "security bug" from "regular bug." That policy exploded the CVE count and made downstream distros' (Ubuntu, RHEL, SUSE) security-tracking work extraordinarily painful — hundreds of "CVE-titled patches" per month, many of which are just plain feature fixes classified as security incidents.

The real problem isn't Linux Kernel itself — they can manage this cadence. The real headache is at cloud providers and security vendors — AWS, GCP, Azure, CrowdStrike, Wiz, all the companies tracking CVE coverage for their customers, now have to render 431 rows in a dashboard on July 19 without embarrassment. That's an engineering problem.

via landiannews