Linux Kernel Nears 2,000 CVEs Per Release as AI Bug Reports Pile Up
Security / analysis
Linux Kernel Nears 2,000 CVEs Per Release as AI Bug Reports Pile Up
Greg Kroah-Hartman's figures show a fourfold jump from the 6.x series, while one vendor's count puts real exploitation signal at 1 in 400.

The Linux kernel is nearing 2,000 CVEs per release, up from roughly 500 for most of the 6.x series, and maintainer Greg Kroah-Hartman attributes the jump to AI tools reading the code.
The figures come from Kroah-Hartman's upcoming Kernel Recipes 2026 presentation, as summarised by Slashdot from a Phoronix report on August 29. Kroah-Hartman, a Fellow at the Linux Foundation and the kernel's stable-release maintainer, is quoted there: "With the proliferation of AI/LLM models analyzing the Linux kernel's vast codebase, there has been a surge in the number of CVEs per release."
Kernel CVEs per release: about 500 to nearly 2,000
Security Boulevard put the progression in three steps in its September 1 report. The count passed 1,000 with Linux 7.0 and exceeded 1,500 with Linux 7.2. Linux 7.3 is on course to approach or pass 2,000.
| Release | CVEs per release | Source |
|---|---|---|
| Linux 6.x series (typical) | about 500 | Slashdot, Security Boulevard |
| Linux 7.0 | more than 1,000 | Security Boulevard |
| Linux 7.2 | more than 1,500 | Security Boulevard |
| Linux 7.3 | approaching 2,000, possibly more | Slashdot, citing Kroah-Hartman's slides |
The kernel project became its own CVE Numbering Authority in February 2024 and assigns a CVE to every fix landing in stable trees that meets the CVE Program's definition of a vulnerability, according to noze.it. That policy turns every AI-found bug fix into a published identifier.
Karthick Palanisamy, a developer quoted by Security Boulevard from a LinkedIn post, argues that "The codebase itself hasn't grown to match" the rise, and that it is "still roughly 34 million lines of C". Other estimates in the same report run past 40 million.
The 432-CVE batch of July 2026, and counts that disagree
On July 19 and 20, 2026 the kernel team published 432 CVEs. Security Boulevard and Zest Security describe that as 24 hours; noze.it says two days and notes some trackers count 440. The sources do not reconcile the gap.
They also disagree on 2024. noze.it gives 4,325 kernel CVEs for the year, while Zest gives a range of 3,108 to 3,529. If two counters cannot agree on a completed year, any per-release trend line carries error bars the headline numbers do not show.
For scale, noze.it sets the July batch beside two vendor cycles: Microsoft's July 14 Patch Tuesday with 570 vulnerabilities and Oracle's July 21 Critical Patch Update with 1,235 unique CVEs.
- Linux kernel (Jul 19-20)432 CVEs
- Microsoft (Jul 14)570 CVEs
- Oracle (Jul 21)1235 CVEs
Source: noze.it, accessed 2026-10-02
Maintainer load: 5 to 10 reports a day
Per noze.it, reports to the kernel security list rose from two or three a week two years earlier to five to 10 a day. On July 21, sysadmin Jan Schaumann opened an oss-security thread saying "this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes".
Kroah-Hartman replied on July 22 that the batch was "a perfect storm of 6 weeks straight of conferences and vacations". He added: "The number of llm-found issues is only on the rise right now, it's going to be very long 18 months at the least to dig ourselves out of this mess."

The score overstates: 56% critical, about 0.25% exploited
Dvir Sasson, Vice President of AI and Security Research at Zest Security, writes that "More than half the queue screams Critical; fewer than one finding in four hundred has evidence behind the scream." Zest puts 56% of kernel CVEs at High or Critical on scanner labels and about 0.25% with a genuine exploitation signal.
Zest's post gives no sample size, date range or dataset definition for those two figures; it refers to "environments we monitor". Treat them as one vendor's measurement, not a census. The same post says 174 kernel CVEs were tagged CVSS 9.0 or higher in the first half of 2026, against 32 across 2021 to 2025.
Kroah-Hartman's own reading points the same way. Per the Phoronix text quoted by Slashdot, "most often they end up being lower priority vulnerabilities and often within old/obscure driver code, so the impact is often minimal."
Exploitation does still happen. On September 18, 2026 CISA added CVE-2025-39964 and CVE-2026-53266, both Linux kernel flaws, to its Known Exploited Vulnerabilities catalog on evidence of active exploitation. Our earlier piece on CISA's three-day deadline for edge flaws covers the directive that sets those dates, and the Citrix NetScaler zero-days show the kind of bug that does earn the label.
What operators can do with 5 to 10 reports a day
noze.it lists four consequences for production systems: update continuously, with livepatch where reboots are costly; keep an inventory so exposure can be judged; rank by exploitability using the KEV catalogue, EPSS and reachability rather than by severity label; and document every exception with a rationale, mitigating controls and an expiry date.
None of the sources fetched for this piece gives a release date for Linux 7.3, so the 2,000 figure stays a projection until that release is tagged.
Sources
More in Security
- 01NVIDIA's OpenShell Agent Sandbox Hits 14,400 Stars: What It Enforces and What It Leaves OutThe Apache 2.0 runtime confines agents with Landlock and seccomp, but its own issue tracker and an outside critique show where the boundary stops.
- 02Apple Says macOS Full Disk Access Will Require 'Very Explicit User Action'An October 2 developer post cites AI agents as the reason, but gives no macOS version, no date and no list of affected apps.
- 03Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 04Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.