This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?
I'm very curious what organisations would have such a policy. I can't imagine it being viable for any size of org without significant self-deception (or banning the use of all open source at which point CVEs are moot anyway).
SQLite Critical CVEs or LLM Slop?
31–40 of 407 posts
Re: SQLite Critical CVEs or LLM Slop?
#32Re: SQLite Critical CVEs or LLM Slop?
#33Re: SQLite Critical CVEs or LLM Slop?
#34Re: SQLite Critical CVEs or LLM Slop?
#35This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?
I'm very curious what organisations would have such a policy. I can't imagine it being viable for any size of org without significant self-deception (or banning the use of all open source at which point CVEs are moot anyway).
I would humbly suggest any org of any size that has insurance cover that covers anything tech related (e.g. data loss/recovery, cyber etc.) has a very good look at the small print.
Over the last few years insurers have aggressively been adding "no vulnerability patch, no claim" exclusion clauses.
Re: SQLite Critical CVEs or LLM Slop?
#36Why is the repo even mixing CVE's for "schreibfaul1 ESP32-audioI2S" and "SQLite"? Is mixing CVE's for different products in one repo common practice?
Re: SQLite Critical CVEs or LLM Slop?
#37Not validating submissions seems like avenue for massive attack. Flood the whole system with endless false reports. Thus making it significantly less reliable.
https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-eve... https://daniel.haxx.se/blog/2024/01/16/curl-is-a-cna/ https://daniel.haxx.se/blog/2025/04/24/how-the-cna-thing-is-...
Re: SQLite Critical CVEs or LLM Slop?
#38Honest take, this is a critical CVE.
Re: SQLite Critical CVEs or LLM Slop?
#39The problem with this kind of thing, is that it reduces the S/N (Signal-to-Noise) ratio, so weeding out the legit CVEs becomes a lot more difficult. But, on the other hand, I do know that LLMs have been discovering a lot of legit CVEs, and I will lay odds that the blackhats are leveraging them to the max.
Re: SQLite Critical CVEs or LLM Slop?
#40This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?