Torvalds: the 'continued flood of AI reports' has made the Linux kernel security list 'almost entirely unmanageable'
In his Linux 7.1-rc4 announcement (May 17, 2026), Linus Torvalds wrote that AI bug-finding tools had flooded the kernel's private security list with duplicate reports. He asked people to send patches instead of raw AI findings. Over the following months kernel CVE counts climbed (432 CVEs in two days in July; reportedly ~2,000 per release by September), and Debian's Sept 29 kernel advisory alone covered more than 1,000 CVEs.
Key facts
- Torvalds (LKML, 7.1-rc4): 'the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools'
- Also: 'People spend all their time just forwarding things to the right people or saying "that was already fixed a week/month ago"'. AI-found bugs are generally not secret, because the same tools are available to everyone. 'If you found a bug using AI tools, the chances are somebody else found it too'
- July 2026: the kernel CNA published 432 CVEs over a single Sunday and Monday; press linked the surge partly to AI-assisted vulnerability research (Techzine, Open Source For You)
- Security Boulevard (Sept 2026): ~500 CVEs per release in the 6.x era, 1,000+ for Linux 7.0, 1,500+ for 7.2 and approaching 2,000 for 7.3. It attributes the rise to AI tools including Anthropic's Mythos and OpenAI's GPT-5.6 Sol scanning old driver code
- Sept 29, 2026: Debian DSA-6528-1 (kernel 6.12.111-1 for Debian 13) fixed 1,000+ CVEs (9to5Linux counts 1,313). The advisory itself does not mention AI; 9to5Linux attributes the size to the kernel's assign-a-CVE-to-every-security-fix policy and Debian batching several upstream releases
- Caveat: since February 2024 the kernel is its own CVE Numbering Authority and assigns CVEs liberally, so CVE counts overstate the rise in serious vulnerabilities
What happened
After frontier models with strong vulnerability-finding skills spread in spring 2026 (Claude Mythos Preview / Project Glasswing, OpenAI's Daybreak), many researchers pointed the same AI tools at the Linux kernel and reported the same bugs to its private security list. Torvalds said the list had become almost unmanageable and asked people to add value with fixes. Kernel CVE output kept rising through the summer, and downstream distributions shipped record-size kernel advisories.
Why it matters
This is a concrete case of AI bug-finding at scale shifting the bottleneck from discovery to triage and patching for volunteer maintainers. It also shows the duplication problem: when everyone runs the same models, AI-found bugs are effectively public.
Changelog
- 2026-10-02: created (leads: Debian DSA-6528-1 / HN; the advisory itself does not attribute the CVEs to AI)
Related events
- Anthropic reveals Claude Mythos Preview, withholds it over cyber risk and launches Project Glasswing ★★★★★
- OpenAI launches Daybreak cyber-defense initiative with GPT-5.5-Cyber and Codex Security ★★★
Sources (7)
- officialLKML: Linus Torvalds, Linux 7.1-rc4 announcement
- pressThe Register: Torvalds says AI-powered bug hunters have made Linux security mailing list 'almost entirely unmanageable'
- pressTechzine: 432 Linux vulnerabilities put pressure on patch management
- pressOpen Source For You: Linux maintainers battle record AI-fuelled CVE surge
- pressSecurity Boulevard: AI helps drive number of Linux kernel CVEs to near 2,000 per release
- docsLWN: Debian DSA-6528-1 kernel security update
- press9to5Linux: Debian 13 kernel security update patches more than 1300 CVEs
id: 2026-05-17-torvalds-ai-bug-reports-linux-security-list · updated 2026-10-02 · open in the interactive timeline