Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Linux kernel vulnerabilities surge to nearly 2,000 per release as AI bug hunters overwhelm maintainers
00

Linux kernel vulnerabilities surge to nearly 2,000 per release as AI bug hunters overwhelm maintainers

Sep 1, 2026

The Linux kernel is approaching a record 2,000 CVEs fixed per release, up from 500 in the 6.x era, as AI bug hunters overwhelm maintainers. Automated tools scanning the 40-million-line codebase generate low-priority reports and hallucinations. Maintainers like Jakub Kicinski report being completely overwhelmed, leading to the removal of legacy drivers to reduce maintenance burdens. In response, stable maintainer Greg Kroah-Hartman has restricted LLM patches while adopting frontier AI models to filter submissions.

Linux kernel CVE surge

  • ▪Linux stable maintainer Greg Kroah-Hartman revealed that Linux kernel CVE counts exceeded 1,000 with Linux 7.0 and 1,500 with Linux 7.2.
  • ▪The Linux kernel is approaching nearly 2,000 Common Vulnerabilities and Exposures (CVEs) fixed per release, up from approximately 500 during the Linux 6.x era.
  • ▪Linus Torvalds released the Linux 7.3-rc1 testing version on August 30, 2026, which could push the Linux kernel CVE count past 2,000 if current trends continue.

AI-driven vulnerability detection

  • ▪Linux kernel CVE records in 2026 have explicitly credited AI-assisted static analysis with identifying vulnerabilities that were subsequently confirmed by Intel Product Security.
  • ▪Many AI-generated bug reports for the Linux kernel consist of low-priority vulnerabilities, questionable patches, and outright hallucinations, requiring human verification to filter.
  • ▪The surge in Linux kernel CVEs is primarily driven by automated tools and large language models scanning the operating system's 40-million-line codebase.

Maintainer workload burden

  • ▪Linux networking maintainer Jakub Kicinski estimated that between one-third and one-half of the 648 net-next patches handled during the Linux 7.3 cycle were low-priority fixes driven by AI.
  • ▪Linux networking maintainer Jakub Kicinski stated that kernel maintainers are completely overwhelmed by the influx of automated bug reports.

Legacy driver removal decisions

  • ▪The Linux 7.3 kernel is removing legacy SGI and IBM driver code, as well as the FreeVxFS filesystem driver, because they primarily serve as fodder for automated bug checkers.
  • ▪In April 2026, developer Andrew Lunn proposed removing nearly 28,000 lines of legacy networking code for old ISA and PCMCIA-era hardware to reduce AI-driven maintenance burdens.

Kernel community AI policy

  • ▪Linux stable maintainer Greg Kroah-Hartman barred large language model-generated patches from the kernel's staging subsystem, except for legitimate security fixes.
  • ▪The Linux kernel development team has secured access to multiple frontier AI models to help review patches, filter out hallucinations, and automate routine administrative work.

1 source

Tomshardware
Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are 'completely overwhelmed' by CVE finds
View source article

Featured stories

View more in Vulnerability disclosure

OpenAI advertising business reaches $1 billion annual run rate

Aug 31, 2026 · 2 sources

Bank of England governor warns AI models threaten global financial stability

Aug 31, 2026 · 4 sources

Anthropic warns Claude users after infostealer malware hijacks active login sessions

Aug 30, 2026 · 4 sources

Trump administration considers new export controls targeting Chinese access to remote AI servers

Aug 28, 2026 · 1 source

Story comments

Loading comments…

Topics

Vulnerability disclosureAI securityAI tools & products

Featured stories

View more in Vulnerability disclosure

OpenAI advertising business reaches $1 billion annual run rate

Aug 31, 2026 · 2 sources

Bank of England governor warns AI models threaten global financial stability

Aug 31, 2026 · 4 sources

Anthropic warns Claude users after infostealer malware hijacks active login sessions

Aug 30, 2026 · 4 sources

Trump administration considers new export controls targeting Chinese access to remote AI servers

Aug 28, 2026 · 1 source