Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Jump to main content
Search
REG AD
Security
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’
Simon Sharwood
Simon<br>Sharwood
APAC Editor
Published<br>mon 18 May 2026 // 00:39 UTC
Linux kernel boss Linus Torvalds has declared the project’s security mailing list has become “almost entirely unmanageable” due to multiple researchers using AI to find bugs and then filling the list with duplicate reports.<br>Torvalds used his weekly state of the kernel post to deliver release candidate four for Linux 7.1 and report “fairly normal” progress towards a full release.<br>He then pointed kernelistas to the project’s documentation, which he wrote “might be worth highlighting” as “the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools.”
REG AD
“People spend all their time just forwarding things to the right people or saying ‘that was already fixed a week/month ago’ and pointing to the public discussion,” Torvalds complained.
REG AD
MORE CONTEXT
Linux 7.1 will have an optional new NTFS driver
AI bug reports went from junk to legit overnight, says Linux kernel czar
Linus Torvalds: Someone ‘more competent who isn't afraid of numbers past the teens’ will take over Linux one day
Linus Torvalds and friends tell The Reg how Linux solo act became a global jam session
The Penguin Emperor believes that kind of chatter is “all entirely pointless churn” and isn’t productive because “AI detected bugs are pretty much by definition not secret, and treating them on some private list is a waste of time for everybody involved – and only makes that duplication worse because the reporters can't even see each other's reports.”<br>He then offered an opinion on how best to use AI to improve software security.<br>“AI tools are great, but only if they actually help, rather than cause unnecessary pain and pointless make-believe work,” he wrote. “Feel free to use them, but use them in a way that is productive and makes for a better experience.”<br>“The documentation may be a bit less blunt than I am,” he added, “but that's the core gist of it.”<br>“So just to make it really clear: If you found a bug using AI tools, the chances are somebody else found it too. If you actually want to add value, read the documentation, create a patch too, and add some real value on *top* of what the AI did. Don't be the drive-by ‘send a random report with no real understanding’ kind of person. OK?”<br>Torvalds' remarks contrast with recent comments from fellow kernel maintainer Greg Kroah-Hartman, who recently told The Register that AI has become an increasingly useful tool for the FOSS community. ®
security<br>linux<br>linux kernel<br>ai<br>linus torvalds
REG AD
Security
Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative
Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government
OSes
Windows boot partition runs out of space for Microsoft's May security update
Testing? We've heard of it
ZTE showcases at GSMA M360 LATAM 2026, driving future business model restructuring - AI & network two-way integration
AI-integrated networks can cut costs, boost 5G efficiency, and help regional telcos shift beyond basic connectivity
Security
F-35 software delays leave UK buying time with US glide bombs
MoD says StormBreaker will plug gap until homegrown SPEAR 3 integration lands
Columnists
Utah tells porn sites to take the P out of VPNs, and it's their fault that they can't
Governments can't touch VPNs technically or commercially. The mess they'll make if they try will be off the scale
Security
Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess
Firefox maker says the tools are basic security infrastructure, not teenage contraband
MOST POPULAR
AI + ML
Google users fight for refunds as unauthorized API usage bills soar
Systems
Europe built sovereign clouds to escape US control. Then forgot about the processors
Security
Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
Security
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Networks
Veteran network architect proposes IPv8 – to improve IPv4, not leapfrog v6
EVENTS
The Hardware Crunch: How Supply Chain Turbulence Is Forcing a New IT Playbook
Infrastructure teams are facing a perfect storm: extended hardware lead times, rising costs driven by AI demand, and accelerated platform timelines.
From Prompt to Exploit: How LLMs Are Changing API Attacks
Modern applications are API-driven,...