10 Sources
[1]
Linus Torvalds admits he has a 'love-hate relationship with AI'
AI continues to be a mixed blessing when it comes to finding and fixing security bugs. Speaking at the Linux Foundation's Open Source Summit North America, Linux creator Linus Torvalds said modern AI tools are reshaping how developers work on the kernel, driving up contribution volume and exposing
[2]
Linus Torvalds says Linux security list is becoming 'unmanageable' due to AI bug reports
Linux founder Linus Torvalds said in his most recent state of the kernel post that "the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools," as The Register
[3]
Flood of duplicate vulnerability reports have made Linux security mailing list 'almost entirely unmanageable' -- Linus Torvalds says private list 'a waste of time for everybody involved' in switch to new public system
New kernel documentation now formally requires AI-found bugs to be reported publicly. Linus Torvalds declared the Linux kernel's private security mailing list "almost entirely unmanageable" on Sunday in his weekly post to the Linux Kernel Mailing List (LKML), blaming a flood of duplicate
[4]
AI eyes scanning for bugs create a worrisome Linux security trend
OPINION Dirty Frag, Copy Fail, and Fragnesia are less a random cluster of Linux bugs and more the public unveiling of how AI tools can pry open security holes with just a prompt or two. What they also have in common is their shared abuse of a core kernel abstraction: The page cache. What does this
[5]
Linux developers are getting bombarded with AI-generated bug reports, and Linus isn't happy
* AI scans flood private security list with duplicate, minor bug reports, making it unmanageable. * Treat AI-detected bugs as public; private reports just hide duplicates and waste maintainers' time. * If AI finds a bug, roll up your sleeves: fix it (don't just send drive-by reports or blame the
[6]
Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend
OPINION Dirty Frag, Copy Fail, and Fragnesia are less a random cluster of Linux bugs and more the public unveiling of how AI tools can pry open security holes with just a prompt or two. What they also have in common is their shared abuse of a core kernel abstraction: The page cache. What does this
[7]
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list 'almost entirely unmanageable'
Linux kernel boss Linus Torvalds has declared the project's security mailing list has become "almost entirely unmanageable" due to multiple researchers using AI to find bugs and then filling the list with duplicate reports. Torvalds used his weekly state of the kernel post to deliver release
[8]
'Almost entirely unmanageable': Linus Torvalds says AI bug hunters have ruined Linux security mailing list
* Linus Torvalds warns AI‑generated bug reports are overwhelming the Linux security mailing list with duplication and noise * He urged researchers to add real value by creating patches instead of submitting random automated findings * Similar concerns have already led projects like curl and
[9]
AI is raising hell for Linux managers buried under a flood of dupe bug reports
Torvalds' latest Linux update warns that AI-assisted reporting can create more maintenance work when contributors skip verification AI may be finding Linux bugs faster than humans can sort them. In the Linux 7.1-rc4 update, Linus Torvalds said the kernel's security list has been swamped by
[10]
'The continued flood of AI reports has basically made the security list almost entirely unmanageable': Linus Torvalds laments how people are wasting the Linux team's time with LLMs
Linux's creator isn't against the use of AI tools, he's just tired of folks using them and then doing nothing with what they've discovered In the world of software, it's common knowledge that Linus Torvalds isn't one to mince his words, and in a post about the latest kernel release candidate on
Share
Copy Link
Linux creator Linus Torvalds revealed that AI-generated bug reports have overwhelmed the kernel's private security mailing list with duplicate vulnerability reports. The flood of AI-found bugs has forced the project to shift toward public disclosure, as multiple researchers independently discover identical issues using the same automated tools.
Linux creator Linus Torvalds has a love-hate relationship with AI, acknowledging the technology as a powerful tool while grappling with its unintended consequences for the open-source community. Speaking at the Linux Foundation's Open Source Summit North America, Torvalds revealed that AI coding tools have driven a 20% increase in commits over the last two releases, marking the first significant shift in the kernel's development pace in two decades
1
. While he emphasized that "AI is a great tool, but it's a tool" rather than a replacement for programmers, the surge in AI-assisted code contributions has exposed new social and security stresses within the Linux kernel project.
Source: The Register
The most pressing issue facing Torvalds and the kernel maintainers is the unmanageable volume of duplicate reports flooding the Linux security mailing list. In his weekly post to the Linux Kernel Mailing List announcing Linux 7.1-rc4, Torvalds declared the private security list "almost entirely unmanageable" due to AI-generated bug reports
2
. The problem stems from multiple researchers running the same AI tools against identical code and independently filing duplicate vulnerability reports on a private channel where nobody can see what has already been submitted. Willy Tarreau, creator of HAProxy and a longtime kernel maintainer, noted that the list has gone from receiving two to three reports per week two years ago to five to 10 reports per day3
. Maintainers now spend their time triaging duplicates and directing reporters to fixes that were merged weeks earlier, creating what Torvalds called "entirely pointless churn."In response to this crisis, Torvalds has formalized new kernel documentation requiring AI-found bugs to be treated as public disclosures rather than private security issues
3
. "If you found a bug using AI tools, the chances are somebody else found it too," Torvalds stated bluntly2
. The new policy directs developers to submit AI-detected bugs directly to relevant maintainers through public channels, formatted in plain text with verified reproducers and a proof of concept. This approach mirrors what Greg Kroah-Hartman, the Linux stable kernel maintainer, has been doing with his "Clanker T1000" system: discover the issue, write the fix, take responsibility for the patch, and submit it publicly3
.
Source: Tom's Hardware
The Linux kernel project formalized its broader stance on AI-assisted code contributions last month, establishing project-wide policies that permit AI-generated code under strict disclosure rules
3
. AI agents cannot use the legally binding "Signed-off-by" tag, and contributors must use a new Assisted-by tag for transparency. Every line of AI-generated code and any resulting bugs remains the legal responsibility of the human who submits it. Torvalds urged researchers to add genuine value beyond raw AI output: "If you actually want to add value, read the documentation, create a patch too, and add some real value on top of what the AI did. Don't be the drive-by 'send a random report with no real understanding' kind of person"2
. This sentiment was echoed by GitHub senior product security engineer Jarom Brown, who emphasized that AI-assisted findings need validation and demonstrated impact rather than volume2
.Related Stories
The rise of AI tools has fundamentally altered the vulnerability discovery timeline, creating new risks for Linux security. Torvalds noted that in the past, the kernel community would quietly notify distributions about bugs without detailing vulnerabilities, and "most of the time, nobody would figure out what happened." Now, with AI-accelerated analysis, "last week, we fixed the bug; within three hours, there was a blog post about the implications of that bug fix"
1
. Recent vulnerabilities like Dirty Frag, Copy Fail, and Fragnesia demonstrate how AI tools can identify security holes with just a prompt or two4
. According to Google Threat Intelligence Group data, the mean time to exploit has plummeted from 63 days in 2018 to -1 day in 2024 and an estimated -7 days in 2025, meaning exploitation now occurs before patches are released4
.
Source: The Verge
Torvalds pushed back against the notion that closing source code offers protection from AI-driven vulnerability discovery. "If you think that AI can't reverse engineer closed source, you're in for a surprise," he warned at Open Source Summit
1
. He argued that "closed source is even worse in this respect, because the AI can't help you fix the problems, but the AI sure can help find those problems in the first place." This prediction is already playing out: Microsoft patched 1,139 CVEs in 2025, the second-highest count behind 2020, with expectations that AI-discovered bugs will drive that number higher in 20261
. Christopher "CRob" Robinson, chief security architect for the Open Source Software Foundation, told The Register that roughly 30 percent of reported Linux security bugs were duplicates, warning that smaller open source projects could be overwhelmed by this new reality4
. Igor Seletskiy, CEO of CloudLinux, noted that companies might have to reboot servers weekly as kernel-level privilege escalation vulnerabilities that once appeared once or twice yearly now surface multiple times per week4
. For developers and system administrators, the message is clear: the era of AI-accelerated vulnerability discovery demands faster response times, better coordination, and a shift from creating patches reactively to proactively hardening code before AI tools expose weaknesses.🟡 означает "Это prediction is already playing out: Microsoft patched 1,139 CVEs in 2025, the second-highest count behind 2020, with expectations that AI-discovered bugs will drive that number higher in 20261
. Christopher "CRob" Robinson, chief security architect for the Open Source Software Foundation, told The Register that roughly 30 percent of reported Linux security bugs were duplicates, warning that smaller open source projects could be overwhelmed by this new reality4
. Igor Seletskiy, CEO of CloudLinux, noted that companies might have to reboot servers weekly as kernel-level privilege escalation vulnerabilities that once appeared once or twice yearly now surface multiple times per week4
. For developers and system administrators, the message is clear: the era of AI-accelerated vulnerability discovery demands faster response times, better coordination, and a shift from creating patches reactively to proactively hardening code before AI tools expose weaknesses."."Summarized by
Navi
[2]
27 Mar 2026•Technology

10 Mar 2026•Technology

31 Jul 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
