• SQLite Critical CVEs or LLM Slop? (JFrog blog)

    From LWN.net@618:250/24 to All on Tue Aug 4 06:40:09 2026
    The JFrog blog examines
    some reported vulnerabilities in SQLite, some of which made their way
    into high-profile vulnerability databases, that turned out to be entirely fabricated by LLMs.

    These LLM slop CVEs can cause organizations to waste time
    investigating and patching vulnerabilities that do not actually
    exist, as well as polluting vulnerability databases. In
    environments where Critical vulnerabilities are automatically
    prioritized or tickets are opened based on vulnerability scores,
    such fabricated CVEs can turn into a real burden.

    In environments where AI is used to automate vulnerability triage
    and remediation this becomes even more concerning. An AI agent that
    encounters a fabricated CVE may attempt to locate the vulnerable
    function, generate a patch, or recommend changes based on code that
    does not even exist. Instead of helping security teams remediate
    real vulnerabilities, it can lead them down a completely wrong
    path, potentially introducing unnecessary changes and wasting time.

    https://lwn.net/Articles/1086936/
    --- SBBSecho 3.37-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (618:250/24)