Chronicle/Defense & research

Maintainers report AI-generated vulnerability reports overwhelming kernel and bounty triage

DefenseIncidentSignificance assistant-drafted

Help Net Security reported that Linus Torvalds described the Linux kernel security list as almost entirely unmanageable because of heavily duplicated AI-assisted reports, and that GitHub tightened its bug bounty submission requirements, with a GitHub engineer saying some programs elsewhere had shut down. The article also notes that curl ended bounty payments after a surge of low-quality AI reports.

Why it matters

Human triage capacity, not discovery, is emerging as the bottleneck for AI-scale vulnerability finding.

Key facts

As stated in the sources, with where to find them.

  • Torvalds is quoted describing the kernel security list as almost entirely unmanageable, with enormous duplication from people finding the same bugs with the same tools.Opening paragraphs (quoting his kernel release-candidate note)
  • GitHub began requiring submitters to validate AI-assisted findings and include a working proof of concept demonstrating exploitation potential and concrete security impact.Paragraphs on GitHub's bounty program

Findings that cite this record

Key questions this bears on

Sources

Related records