At Kernel Recipes 2026, Linux maintainer Greg Kroah-Hartman talks to kernel developers about the flood of LLM-assisted security reports. The 34-minute talk is followed by roughly 22 minutes of questions. His refrain is don’t panic—but do the work.

A claimed bug count is not a triaged vulnerability count

  • Kroah-Hartman walks through a widely publicized batch of purported findings from Anthropic’s Mythos. His review found nonexistent reports, duplicates of already-public fixes, issues outside the kernel’s security threat model, and some real bugs. He argues that the headline count badly overstated the security impact.
  • AI tools can spot analogous unfixed code paths by comparing them with past fixes. That can be useful, but the same tools also recycle old reports and generate convincing-looking patches for problems that do not exist.
  • A crash in an obscure configuration is not automatically an exploitable security flaw. The context and threat model matter.

The burden moves to maintainers

  • In a review exercise with six graduate students, he says roughly half the plausible-looking generated patches they inspected were wrong, inapplicable, unneeded, or failed to solve the stated issue. That’s his exercise, not a universal benchmark.
  • A verbose, persuasive changelog can obscure bad code. Review the diff, request a reproducer and test evidence, and ask the submitter to explain the change; maintainers need not accept a wall of untriaged reports.
  • He wants reporters to include a patch and copy the relevant maintainer. A patch is not proof, but forcing a concrete proposed fix can expose false positives before they consume more review time.

Fixes only help when deployed

  • His larger worry is the lag between finding a bug and updating deployed systems. Automated attackers may chain small flaws while organizations leave known fixes unapplied.
  • He compares this wave to fuzzing: fix real bugs, document subsystem threat models, remove unused code where appropriate, and keep working through the backlog rather than treating every generated finding as an emergency.
  • For nonpublic security material, he recommends local models instead of uploading reports or code to hosted services. The Q&A also stresses accountability: small, tested contributions and a responsive human submitter build trust.

“Do not panic.” — Greg Kroah-Hartman