Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are ‘completely overwhelmed’

Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are 'completely overwhelmed'

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works .

Rather than a change in Linux’s security or a rise in vulnerabilities, the spike is mainly due to “detectives” using AI tools to scour the Linux kernel source tree, which has grown to over 40 million lines over 35 years of Linux’s existence . These tools can examine countless obscure sections humans may rarely revisit, occasionally finding genuine defects; Linux CVE records this year already explicitly credit AI-assisted static analysis with finding vulnerabilities subsequently confirmed by Intel Product Security. However, many of the findings have been low-priority vulnerabilities — often within obscure driver code — questionable patches, and outright hallucinations, leaving human maintainers to separate useful work from noise.

This problem already constitutes a nuisance for kernel teams that have to fix these issues. In the Linux 7.3 networking pull request, maintainer Jakub Kicinski estimated that between one-third and one-half of the 648 net-next patches handled during the cycle appeared to be low-priority fixes, clean-ups, or clarifications driven by AI. "We are completely overwhelmed,” Kicinski wrote.

The issue has also led Linux maintainers to question whether decades-old drivers are worth keeping alive. In April, developer Andrew Lunn proposed removing nearly 28,000 lines of legacy networking code covering old ISA and PCMCIA-era hardware. While these drivers historically required little attention because they barely had any users, the AI and fuzzing tools started finding defects that maintainers were obligated to investigate and fix, regardless of whether anyone actually runs the hardware.

Linux 7.3 is removing old SGI and IBM driver code, while other ancient components have also been retired as maintainers reassess whether their compatibility value justifies their new maintenance cost. The FreeVxFS filesystem driver, for example, was removed after its maintainer said the decades-old compatibility code now largely served as fodder for automated bug checkers.

Linus Torvalds rebukes anti-AI stances in the Linux kernel code review process, says 'Linux is not one of those anti-AI projects'

Linux developers are using AI vibe coding to keep vintage AMD GPUs alive

Key considerations

  • Investor positioning can change fast
  • Volatility remains possible near catalysts
  • Macro rates and liquidity can dominate flows

Reference reading

More on this site

Informational only. No financial advice. Do your own research.

Leave a Comment