Linux Open-Source Blessing Has a 19-Year-Old Bug Problem
A 19-year-old networking bug has been discovered in the Linux kernel codebase—nobody ran that specific test sequence for two decades. Researcher Jenny Guanni Qu’s analysis of 125,183 bug fixes since 2005 reveals an average bug lifespan of 2.1 years, with 13% persisting for five years or more.
Qu’s statistical analysis shows 20% of 2025 bug fixes addressed issues with five+ year lifespans due to time-bound data skew.
The VulnBERT AI model claims a 92.2% detection rate for bug-introducing commits. Qu warns: "Bugs introduced in 2022 can't have a 10-year lifetime yet..."
Qu explains: "Of all actual bug-introducing commits, we catch 92.2%" through the AI model. The researcher adds: "We're simultaneously catching new bugs faster AND slowly working through ~5,400 ancient bugs..."