IBM and Red Hat have identified and fixed more than 400 previously unknown vulnerabilities in widely used open-source software. These vulnerabilities affect Java libraries used in enterprise applications. With Lightwell, the companies aim not only to detect vulnerabilities but also to provide patches for software versions that are actually in production at organizations.
The latter is a key part of the initiative. Security scanners can alert organizations that a component they’re using is vulnerable, but that doesn’t solve the problem. Moreover, upgrading to a newer version isn’t always straightforward. Applications may depend on a specific version of a library, and switching could affect other parts of the software.
Patches for older versions
IBM and Red Hat are therefore also focusing on bringing fixes back to older versions, a process known as backporting. According to the companies, the more than 400 vulnerabilities addressed within Lightwell were found in widely used software that is actually running in production environments. The companies have not disclosed which Java libraries were vulnerable.
AI is used in the development of patches. Red Hat states in its technical documentation that AI-generated patches are not automatically distributed to customers. They are first tested and validated by humans. Signed versions can then be incorporated into existing development processes via secure repositories. Supported platforms include Maven, Nexus, and Artifactory.
The companies also point to a new threat posed by AI. Autonomous agents can combine various vulnerabilities, each of which is less severe on its own, into an attack with more serious consequences. As a result, vulnerabilities in older software, once considered stable, may once again become attractive targets for attackers.
Part of a multi-billion investment
Lightwell was announced in May as a $5 billion investment in open-source software security. IBM and Red Hat stated that they would be able to deploy more than 20,000 engineers to the initiative. In July, Lightwell Network launched commercially with over 6,500 patched and digitally signed software dependencies for Java, Python, and other languages.
Now, Lightwell Clearinghouse is also becoming generally available. This allows enterprise customers to submit specific open-source dependencies that require priority investigation. Patches can also be created for older versions that an organization is still using.
Lightwell maintains a separate repository for vulnerabilities that have not yet been disclosed publicly. This allows customers to apply a fix before details about the vulnerability become public. Once a vulnerability has been disclosed in accordance with the responsible disclosure procedure and the patch has been incorporated upstream, the fix can be moved to the regular repository.
IBM and Red Hat are primarily aiming to shorten the time between discovering a vulnerability and actually resolving it. With open-source components in older enterprise applications, this is often more complicated than simply installing the latest software version.