Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are 'completely overwhelmed' by CVE finds

The Linux kernel is approaching a staggering 2,000 CVEs fixed per release, up from roughly 500 through much of the Linux 6.x era, as AI and large language models increasingly scour the operating system’s enormous codebase for vulnerabilities. According to an August 28 Phoronix report, Linux stable maintainer Greg Kroah-Hartman revealed the trend in a slide teasing an upcoming presentation at Kernel Recipes 2026, showing CVE counts jumping above 1,000 with Linux 7.0 and exceeding 1,500 with Linux 7.2. If the current trajectory continues, Linux 7.3 could push the figure beyond 2,000.

Rather than a change in Linux’s security or a rise in vulnerabilities, the spike is mainly due to “detectives” using AI tools to scour the Linux kernel source tree, which has grown to over 40 million lines over 35 years of Linux’s existence. These tools can examine countless obscure sections humans may rarely revisit, occasionally finding genuine defects; Linux CVE records this year already explicitly credit AI-assisted static analysis with finding vulnerabilities subsequently confirmed by Intel Product Security. However, many of the findings have been low-priority vulnerabilities — often within obscure driver code — questionable patches, and outright hallucinations, leaving human maintainers to separate useful work from noise.


Source: www.tomshardware.com…

We will be happy to hear your thoughts

Leave a reply

Forlifedeals
Logo
Compare items
  • Total (0)
Compare
0