Linus Torvalds Says Linux Security List Unmanageable Due to AI Bug Flood

Linus Torvalds declares the Linux kernel's private security mailing list unmanageable due to a flood of duplicate AI-generated vulnerability reports, releasing 7.1-rc4 with new public disclosure policies.

Linus Torvalds Says Linux Security List Unmanageable Due to AI Bug Flood

Linus Torvalds has declared the kernel's private security mailing list "almost entirely unmanageable" due to a flood of duplicate vulnerability reports generated by AI tools. The list now receives 5 to 10 reports per day, up from 2 to 3 per week two years ago, according to kernel developer Willy Tarreau.

Torvalds releases 7.1-rc4 with new guidelines

Torvalds released Linux 7.1-rc4 alongside new documentation that formalizes how the project handles AI-assisted bug reports. Under the new policy, AI-detected bugs should be treated as public disclosures and submitted directly to maintainers, not to the private security list. Torvalds said that AI detected bugs are "pretty much by definition not secret" and that treating them on a private list is "a waste of time for everybody involved."

The kernel project formalized a policy on AI-assisted contributions last month. It requires an "Assisted-by" tag and holds humans responsible for the content. Torvalds urged researchers to create patches and add real value beyond raw AI findings. "If you actually want to add value, read the documentation, create a patch too, and add some real value on top of what the AI did," he said.

The change marks a shift in how the open-source project manages security vulnerabilities. By moving AI-generated reports to public channels, the kernel community aims to reduce noise on the private list and encourage more constructive contributions. The new documentation provides clear guidelines for developers and researchers submitting AI-assisted work.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion