Graph comparing the average lifetime (in years) of security flaws in the Linux kernel from 2010 to 2024, along with number of fixed flaws. Both are 12 months rolling window. The lifetime graph from 2010 to 2023 grows slowly over time, becoming relatively flat at about 6-7 years from 2016 until 2023, where it starts a clear downturn. Over the same time span, the number of security flaw fixes landing has increased (though it is starting to slightly bend toward a flat rate).
This graph is the one I'm most excited about: the lifetime of security flaws in Linux is finally starting to get shorter (and the number of fixed flaws continues to rise).
hachyderm.io/@LinuxSecSum...