The Linux kernel now logs more than 1,500 CVEs per release
Evan / Policy and Open Source desk
The Linux kernel used to log about 500 security vulnerabilities per release. Version 7.2 crossed 1,500, and the reporters filing them are increasingly machines.
The numbers
The figures come from a slide Greg Kroah-Hartman shared ahead of Kernel Recipes 2026, reported by Phoronix on August 28: roughly 500 CVEs per release from Linux 6.9 through 6.19, more than 1,000 per release from 7.0, and over 1,500 for 7.2. Tom’s Hardware ran the same data under a headline saying the kernel “nears record 2,000 vulnerabilities per release” and that maintainers say they are “completely overwhelmed.” The reason both outlets give is the same: AI and LLM tools now scan the kernel’s roughly 40 million lines of code and report everything they find.
What “everything” means
Most of the new CVEs are low-priority problems in obsolete driver code with minimal real-world impact. Under the kernel’s process each one still has to be triaged, assigned and tracked, and the humans doing that work did not triple in number.
The other side of AI bug hunting
This is the flip side of every “AI found a zero-day” story. The same tools that catch real bugs also bury maintainers in paperwork, and the projects everything runs on are staffed by a few dozen volunteers and sponsored engineers. The story reached the top of r/technology on September 1 with 1,893 upvotes. The practical question for the ecosystem is whether AI-generated reports should be filtered or rate-limited before they reach the people who have to read them.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.