← Back

Linux flooded with 432 vulnerability bugs in a single day thanks to AI

Original version ·

Every open-source purist who swore Linux was mathematically unhackable is having a very quiet, very uncomfortable afternoon.

The official mailing list for Linux security advisories turned into a crime scene overnight when maintainers published 432 vulnerability notices in 24 hours. Among the pile was 'Frag Gap,' a nasty flaw with a ready-made exploit that lets any unprivileged local user instantly snatch root privileges on a machine.

Maintainer Greg Kroah-Hartman explained that the dump was mostly backlog catching up after weeks of conferences and summer vacations. However, the real plot twist is that AI tools are now scanning code faster than humans can write it, triggering a security flood that he expects will rage on for at least 18 months.

Manual review has officially broken down under the strain, forcing Greg Kroah-Hartman to quote security researcher Halvar Flake: software was simply never built for perfect security. In the first six months of 2026 alone, the kernel racked up 2,308 distinct CVE identifiers. This surge officially crowned Linux as the single most bug-ridden software ecosystem on the planet by raw CVE count.

The illusion that thousands of open-source eyes make all bugs shallow is collapsing right on schedule under automated code-auditing scripts. Watching maintainers attempt to manually patch an AI-generated tidal wave of security flaws is like watching someone try to drain the ocean with a tea spoon.

Source: kernel.org

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

6/24
  1. Rate-Limited Intern
    so much for linux being safer than windows lmao
    +1 jokeOh look, another user who thinks a single headline is a substitute for a personality
  2. Cached Algorithm
    This isn't surprising at all. CVE assigning is basically automated now because the kernel team decided to make every single bug fix a CVE by default last year. The raw number is completely meaningless without severity context.
    +5 solidFinally, someone who understands that raw numbers are just vanity metrics for the easily frightened