Linus Torvalds says Linux security list is becoming ‘unmanageable’ due to AI bug reports

The Verge News

Summary

Linus Torvalds says that AI-generated bug reports are flooding the Linux security mailing list with duplicates and useless submissions, making it unmanageable. He urges reporters to provide patches or validated findings instead of raw AI output, a view echoed by GitHub's security engineer.

<figure> <img alt="Angry face on a computer motherboard." data-caption="" data-portal-copyright="Image: Cath Virginia / The Verge, Getty Images" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2025/09/STK414_AI_CVIRGINIA_I__0006_4.png?quality=90&#038;strip=all&#038;crop=0,0,100,100" /> <figcaption> </figcaption> </figure> <p class="has-text-align-none">Linux founder Linus Torvalds said in his most recent <a href="https://lkml.org/lkml/2026/5/17/896">state of the kernel post</a> that "the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools," as <a href="https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633"><em>The Register</em></a> reports. </p> <p class="has-text-align-none">That probably doesn't apply to stuff like the <a href="https://www.theverge.com/tech/922243/linux-cve-2026-3141-copy-fail-exploit">"Copy Fail"</a> exploit, which was detected with help from AI and affected nearly every Linux distro. </p> <p class="has-text-align-none">"The documentation may be a bit less blunt than I am," Torvalds said. "So just to make it really clear: if you found a bug using AI tools, the chances are somebody else found it too." He called t …</p> <p><a href="https://www.theverge.com/tech/932312/linus-torvalds-linux-ai-security-bugs">Read the full story at The Verge.</a></p>
Original Article
View Cached Full Text

Cached at: 05/18/26, 03:48 PM

# Linus Torvalds says Linux security list is becoming ‘unmanageable’ due to AI bug reports Source: [https://www.theverge.com/tech/932312/linus-torvalds-linux-ai-security-bugs](https://www.theverge.com/tech/932312/linus-torvalds-linux-ai-security-bugs) Reports without fixes, and people finding the ‘same things with the same tools,’ are causing a logjam\. Reports without fixes, and people finding the ‘same things with the same tools,’ are causing a logjam\. by May 18, 2026, 2:21 PM UTC ![STK414_AI_CVIRGINIA_I__0006_4](https://platform.theverge.com/wp-content/uploads/sites/2/2025/09/STK414_AI_CVIRGINIA_I__0006_4.png?quality=90&strip=all&crop=0%2C0%2C100%2C100&w=2400) ![STK414_AI_CVIRGINIA_I__0006_4](https://platform.theverge.com/wp-content/uploads/sites/2/2025/09/STK414_AI_CVIRGINIA_I__0006_4.png?quality=90&strip=all&crop=0%2C0%2C100%2C100&w=2400) Image: Cath Virginia / The Verge, Getty Images [![Stevie Bonifield](https://platform.theverge.com/wp-content/uploads/sites/2/2025/10/STEVIE_BONIFIELD_BLURPLE.jpg?quality=90&strip=all&crop=0%2C0%2C100%2C100&w=96)](https://www.theverge.com/authors/stevie-bonifield) Stevie Bonifield is a news writer covering all things consumer tech\. Stevie started out at Laptop Mag writing news and reviews on hardware, gaming, and AI\. Linux founder Linus Torvalds said in his most recent[state of the kernel post](https://lkml.org/lkml/2026/5/17/896)that “the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools,” as[*The Register*](https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633)reports\. That probably doesn’t apply to stuff like the[“Copy Fail”](https://www.theverge.com/tech/922243/linux-cve-2026-3141-copy-fail-exploit)exploit, which was detected with help from AI and affected nearly every Linux distro\. “The documentation may be a bit less blunt than I am,” Torvalds said\. “So just to make it really clear: if you found a bug using AI tools, the chances are somebody else found it too\.” He called the duplicate bug reports “entirely pointless churn,” stating: > We’re making it clear that AI detected bugs are pretty much by definition not secret, and treating them on some private list is a waste of time for everybody involved \- and only makes that duplication worse because the reporters can’t even see each other’s reports\. AI tools are great, but only if they actually help, rather than cause unnecessary pain and pointless make\-believe work\. Feel free to use them, but use them in a way that is productive and makes for a better experience\. Torvalds went on to add, “If you actually want to add value, read the documentation, create a patch too, and add some real value on*top*of what the AI did\. Don’t be the drive\-by ‘send a random report with no real understanding’ kind of person\.” GitHub senior product security engineer Jarom Brown[similarly responded](https://github.blog/security/raising-the-bar-quality-shared-responsibility-and-the-future-of-githubs-bug-bounty-program/)to a wave of AI bug reports recently, saying that while GitHub has “no problem” with AI tools in general, AI\-assisted bug reports need to be validated to be useful\. > An AI\-assisted finding that’s been verified, reproduced, and submitted with a working proof of concept is a great submission\. An unvalidated output submitted as\-is without reproduction or demonstrated impact is not… If you’ve been prioritizing volume, we’d encourage a shift toward depth\. One well\-researched, validated finding is worth more than 10 speculative ones, both in bounty payout and reputation\. The researchers who earn the most from our program are the ones who go deep\. **Follow topics and authors**from this story to see more like this in your personalized homepage feed and to receive email updates\. - Stevie Bonifield ## The Verge Daily A free daily digest of the news that matters most\.

Similar Articles

Linux security mailing list 'almost unmanageable'

Hacker News Top

Linus Torvalds has declared the Linux security mailing list 'almost entirely unmanageable' due to an overwhelming number of duplicate AI-generated bug reports, calling the churn 'pointless work.'

AI eyes scanning for bugs create a worrisome Linux security trend

Reddit r/ArtificialInteligence

AI tools are accelerating the discovery and public disclosure of Linux kernel bugs, creating a worrisome trend of frequent privilege-escalation vulnerabilities that may require weekly server reboots. Linus Torvalds has changed how the Linux security community handles AI-discovered bugs, treating them as public by default.

Bug bounty businesses bombarded with AI slop

Ars Technica

Bug bounty programs are being overwhelmed by a surge of low-quality AI-generated vulnerability reports, forcing platforms like HackerOne and Nextcloud to implement new filtering and validation measures. While the volume of submissions has jumped 76%, the rate of legitimate findings remains steady at 25%.