Linus Torvalds says flood of duplicate AI-generated vulnerability reports have made Linux security mailing list 'almost entirely unmanageable' — private list 'a waste of time for everybody involved' in switch to new public system

Linux
(Image credit: Getty)

Linus Torvalds declared the Linux kernel's private security mailing list "almost entirely unmanageable" on Sunday in his weekly post to the Linux Kernel Mailing List (LKML), blaming a flood of duplicate vulnerability reports generated by researchers running the same AI tools against the same code. The complaint accompanied the release of Linux 7.1-rc4 and a pointer to newly merged documentation that formalizes how AI-assisted bug reports should be handled.

The problem, according to Torvalds, is the combination of volume and redundancy: multiple researchers are independently discovering identical bugs using automated tools and filing them separately on a private mailing list, where nobody can see what has already been submitted. Maintainers end up spending their time triaging duplicates and directing reporters to fixes that were merged weeks earlier.

Latest Videos From

This Torvalds-endorsed approach is exactly what fellow maintainer Greg Kroah-Hartman has been doing with his “Clanker T1000” system, a Framework Desktop-powered bug-finding tool: discover the issue, write the fix, take responsibility for the patch, and submit it publicly.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Luke James
Contributor

Luke James is a freelance writer and journalist.  Although his background is in legal, he has a personal interest in all things tech, especially hardware and microelectronics, and anything regulatory. 

  • wakuwaku
    Torvalds urged researchers to go further than filing raw findings. "If you actually want to add value, read the documentation, create a patch too, and add some real value on top of what the AI did," he wrote. "Don't be the drive-by 'send a random report with no real understanding' kind of person."
    Excellent! Now let's all hope Mr. Tom and his lackeys read this and understand that they should also practice the same thing. If all you do is just copy and paste the exact output of an AI as an article, where is your value?
    As long as you all keep up all this <Mod Edit>, we readers will keep on pointing it out. Don't like it? Then fix your it <Mod Edit>.
    Reply
  • xiq
    wakuwaku said:
    Excellent! Now let's all hope Mr. Tom and his lackeys read this and understand that they should also practice the same thing. If all you do is just copy and paste the exact output of an AI as an article, where is your value?
    As long as you all keep up all this ..., we readers will keep on pointing it out. Don't like it? Then fix your ....
    Seems like an ok article to me, nothing groundbreaking but interesting and concise. Are you suggesting it's written by an llm or that you just don't like the writing? Can you explain what's got you so mad?
    Reply
  • blppt
    I wonder if AI will be the thing that finally gets Linus to say "I'm done" and retire. He's been hinting about stepping back for a while.
    Reply
  • HardwiredWireless
    Frankenstein's monster begins to turn on him.
    Reply