The continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools. People spend all their time just forwarding things to the right people or saying “that was already fixed a week/month ago” and pointing to the public discussion.
Which is all entirely pointless churn, and we’re making it clear that AI detected bugs are pretty much by definition not secret, and treating them on some private list is a waste of time for everybody involved - and only makes that duplication worse because the reporters can’t even see each other’s reports.
AI tools are great, but only if they actually help, rather than cause unnecessary pain and pointless make-believe work. Feel free to use them, but use them in a way that is productive and makes for a better experience.
The documentation may be a bit less blunt than I am, but that’s the core gist of it. So just to make it really clear: if you found a bug using AI tools, the chances are somebody else found it too. If you actually want to add value, read the documentation, create a patch too, and add some real value on top of what the AI did. Don’t be the drive-by “send a random report with no real understanding” kind of person. Ok?
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Submitted 19 hours ago by cm0002@infosec.pub to linux@sh.itjust.works
https://lkml.org/lkml/2026/5/17/896
fonix232@lemmy.world 18 hours ago
This sounds like literally an issue AI should excel at.
“Before submitting a bug report, analyse the past 3-4 weeks of the security list to see if the same issue was reported”
lurch@sh.itjust.works 18 hours ago
But the OP says, they can’t see the duplicate reports of others. Probably an open zero-day safety measure. idk
zwerg@feddit.org 17 hours ago
Doesn’t need to be the submitter, could be a filter that runs on Linus’s own laptop
ramble81@lemmy.zip 16 hours ago
“Due to the non-deterministic nature of AI, a similar bug was found but is a few characters off, so we’re classifying this as an all new bug”