Linus Torvalds says flood of duplicate AI-generated vulnerability reports have made Linux security mailing list 'almost entirely unmanageable' — private list 'a waste of time for everybody involved' in switch to new public system
Source
Published
TL;DR
AI GeneratedLinus Torvalds expressed frustration with the Linux kernel's private security mailing list being overwhelmed by duplicate vulnerability reports generated by AI tools. He emphasized the need for a new public system for handling AI-detected bugs, directing researchers to submit findings directly to maintainers as public disclosures. The volume of duplicate reports has strained the existing triage process, prompting Torvalds to urge researchers to provide more value by creating patches along with bug reports. The Linux kernel project recently established a policy allowing AI-generated code with strict disclosure requirements, ensuring human accountability for all AI-assisted contributions.