GNOME项目主管近日阐述了AI驱动漏洞扫描在现代软件安全中的核心地位1。他指出,到2026年,维护高质量软件已离不开AI漏洞扫描工具的支持1。GNOME和WebKitGTK项目因采用AI扫描而发现的CVE数量大幅增长,相比三年前增加了一个数量级1。其中,WebKitGTK 2026年的增长完全源于对Skia和ANGLE的AI分析1。
GNOME项目的bug赏金计划曾颁发€183,900奖金用于处理71个漏洞,其中包括libsoup中的45个、GLib中的23个和glib-networking中的3个1。该计划的最后一份bug赏金报告于2026年2月23日提交1。主管指出,该计划因报告数量过多而无法继续运营。在此期间,Red Hat通过GLib扫描发现了118个漏洞,但其中46个被判为假阳性,虚假正率达40%1。
主管提议GNOME项目维护AI贡献政策,允许AI生成的漏洞报告被纳入正式流程1。他进一步主张,禁止此类报告的项目不应作为GNOME的依赖项1。与此同时,Codean Labs进行的安全审计在Flatpak和xdg-desktop-portal中发现了关键漏洞,包括两个Flatpak沙箱逃逸缺陷1。
The GNOME project's leadership has highlighted artificial intelligence-driven vulnerability scanning as essential to maintaining software security in 2026 1. According to insights shared by the project lead, AI-powered analysis has become indispensable for identifying flaws in modern software, with GNOME and WebKitGTK experiencing a dramatic surge in discovered vulnerabilities that has increased by an order of magnitude compared to three years prior 1. The GNOME bug bounty program distributed €183,900 in rewards across 71 vulnerabilities before closing in February 2026, with 45 flaws found in libsoup, 23 in GLib, and 3 in glib-networking, with the final report submitted on February 23, 2026 1.
The scale of AI-assisted discovery has transformed vulnerability detection practices. Red Hat's scanning of GLib uncovered 118 potential vulnerabilities, though 46 proved to be false positives in gobject-introspection, yielding a 40 percent false-positive rate 1. The growth in WebKitGTK vulnerabilities during 2026 stemmed entirely from AI analysis of Skia and ANGLE components 1. Meanwhile, a security audit conducted by Codean Labs identified critical flaws in Flatpak and xdg-desktop-portal, including two sandbox escape vulnerabilities in Flatpak 1.
The project leadership has proposed establishing an AI contribution policy that permits vulnerability reports generated by artificial intelligence, arguing that projects refusing to accept such findings are unsuitable as dependencies for GNOME 1. This stance reflects a broader acceptance that automated scanning has become central to the software maintenance paradigm, even as questions persist about the balance between algorithmic detection and human-led security reviews 1.
评论
还没有评论,欢迎留下第一条。