Kroah-Hartman Tells Kernel Recipes 'Don't Panic' as Linux CVEs Pass 1,500 a Release
Software / news
Kroah-Hartman Tells Kernel Recipes 'Don't Panic' as Linux CVEs Pass 1,500 a Release
The kernel's CVE count per release has roughly tripled since the 6.x series, and a security vendor says counts overstate severity.

Greg Kroah-Hartman, a Linux kernel maintainer, gave a talk at Kernel Recipes 2026 in Paris titled "Security in the LLM age", and its message is "Don't Panic". The video reached 328 points on Hacker News. The numbers behind it are in his slides: kernel CVEs per release have roughly tripled.
The talk was held Sept. 21 to 23, according to Phoronix, which reported the slide figures on Aug. 28. Montana Linux, which linked the recording on Oct. 2, summarised it as an account of how life has changed over the past year because of LLMs and a sharp rise in CVEs.
The Terminal has not watched the video. What follows rests on the slides as reported by Phoronix, Kroah-Hartman's earlier public remarks and a security-vendor analysis.
CVEs per kernel release, from the slides
Phoronix reports that Linux 6.9 through 6.19 each carried about 500 CVEs. Linux 7.0 passed 1,000, and Linux 7.2 passed 1,500. The same report says Linux 7.3 may reach about 2,000.
- Linux 6.9 to 6.19 (about)500 CVEs
- Linux 7.0 (over)1000 CVEs
- Linux 7.2 (over)1500 CVEs
Source: Phoronix, Aug. 28, 2026, citing Kroah-Hartman's Kernel Recipes 2026 slides
Kroah-Hartman also said that the source tree is about 40 million lines, which gives LLM-driven scanners a large area to search. Karthick Palanisamy, a developer writing in Security Boulevard, put the codebase nearer 34 million lines of C and argued it had not grown to match: "What changed isn't the kernel. It's who's reading it." The two line counts differ, and the sources do not say why.
The "slop" turned into real reports
The turn came earlier in the year. In a March interview reported by The Register, Kroah-Hartman said: "Months ago, we were getting what we called 'AI slop,' AI-generated security reports that were obviously wrong or low quality." Then: "Something happened a month ago, and the world switched. Now we have real reports."
He said he did not know the cause, which could be better tools, new methods or coordinated effort across organisations. In a test with what he called a "really stupid prompt", about one third of 60 AI-suggested fixes were wrong and two thirds worked but needed human work on changelogs and integration. The kernel team runs Sashiko, now a Linux Foundation project, on nearly all patches to reduce reviewer load.
Counting is not the same as severity
More CVEs do not mean more exploitable kernels. Dvir Sasson, VP of AI and Security Research at Zest Security, wrote in the same Security Boulevard piece: "More than half the queue screams Critical; fewer than one finding in four hundred has evidence behind the scream."
Sasson's remark is about vulnerability queues in general, and none of the sources breaks the kernel's 1,500 into severity bands. A reader comparing 500 to 1,500 is looking at a workload for maintainers and distribution patch teams, and the sources offer no measure of risk to a server owner.
What to watch
The next number is the Linux 7.3 count. If it lands near 2,000 as the slides project, the stable team will have handled four times the 6.x volume. The AI-agent side of this problem has already shown up elsewhere, including in the exploited Zammad flaws CISA listed and the GitLab AI Gateway sandbox escape.
Sources
More in Software
- 01OpenCut Has 92,200 Stars, but the Editor People Use Is the Classic One and the Rewrite Is Not Taking ContributionsThe open-source CapCut alternative rebuilt its default branch in May. The README and a third-party walkthrough disagree on how much of the new code is Rust.
- 02Impeccable's Design Detector Runs Without a Model, but Its Open Issues Show Gaps Outside .htmlPaul Bakaus's design skill for coding agents ships 61 deterministic rules you can run from the command line. The bug tracker says where they are least reliable.
- 03A Hacker News Post Says Agents Need Documentation, Not Memory, and Its Author Wrote the Plugin That Does ThatKevin Liao's October 3 essay attacks snippet-recall memory plugins and promotes Operator Memory. A separate September essay argues the real gap is neither memory nor documents.
- 04Agent Reach, at 90,900 Stars, Reads X and Reddit for Your Agent Through Your Own CookiesThe MIT-licensed CLI routes agents to 20-plus sites with a backup backend per channel. Its README admits the login channels can get an account banned.