In 24 hours, Linux fixed more than 400 security vulnerabilities in its kernel. This record is largely due to artificial intelligence, now massively adopted by security researchers.
Mirroring Google and Microsoft, Linux has its work cut out for it due to the rise of artificial intelligence. Armed with generative AI, researchers are discovering more and more vulnerabilities, which gives a lot of work to the teams responsible for ensuring the security of Linux. As recently mentioned Linus Torvaldsthe creator of Linux, developers are currently overwhelmed with vulnerabilities that need to be fixed without delay.
More than 400 flaws fixed in the Linux core
Between July 19 and 20, 2026, Linux has also corrected more than 400 vulnerabilities identified in its core. The official Linux vulnerability archive shows an exceptional volume of publications over these two days. Indeed, such an influx of patches in such a short time is largely out of the ordinary, even for Linux.
The vulnerabilities fixed concern essential building blocks of the Linux systemsuch as Bluetooth, Wi-Fi, firewall, memory management or even file sharing on the network. The failures are mainly memory safety problems, very common in Linux code. For system administrators and businesses that operate Linux servers, it is important to install all patches promptly. If forgotten, computers will continue to be vulnerable. Note, however, that not all Linux vulnerabilities correspond to flaws that can be exploited remotely by an attacker. Sometimes breaches only result in stability issues.
Also read: Millions of vulnerable sites – two critical flaws have been discovered in the core of WordPress
A hunt led by AI
This wave of fixes stems from the gradual integration of AI-based detectors. As early as May 2025, OpenAI’s o3 model made it possible to detect a zero-day flaw in the ksmbd component, simply by analyzing the source code. Since this first feat of arms, the phenomenon has clearly accelerated. Tools like Sashiko, initially developed by Google and then sold to the Linux Foundation, now run on almost all of the patches submitted to the kernel and are gradually being integrated into official review processes.
In the eyes of Greg Kroah-Hartman, historic maintainer of the kernel, the reports generated by AI, long described as “AI slop” have really become exploitable during the year 2026. Vulnerabilities, dormant for sometimes almost a decade, have also been uncovered this year. This is the case of Copy Fail, a vulnerability which dates back more than nine years, and which was plugged last April. The same mechanism is found in the DirtyFrag or Fragnesia faults, identified a few days later.
Linux is forced to tighten the screw
Faced with the explosion of AI-assisted discoveries, Linux has been forced to introduce new rules to guide researchers. Reports must now be short, clear, verified on a real machine, and researchers are invited to use AI to suggest fixes rather than to multiply alerts. This problem goes beyond Linux. According to Greg Kroah-Hartman, all major open source projects have been experiencing the same deluge of disclosures for months.
👉🏻 Follow tech news in real time: add 01net to your sources on Google, and subscribe to our WhatsApp channel.
Source :
Linux
