Linus Torvalds says flood of duplicate AI-generated vulnerability reports have made Linux security mailing list 'almost entirely unmanageable' — private list 'a waste of time for everybody involved' in switch to new public system

TL;DR AI
2 min readKey summary
Linus Torvalds said the Linux kernel’s private security list is becoming nearly unmanageable because many researchers are submitting the same AI-found bugs.
New guidance now points reporters to contact maintainers publicly with a short proof of concept and, ideally, a patch.
The shift reflects how AI-assisted bug hunting is increasing duplicate reports and forcing the project to tighten disclosure workflows.
It also aims to cut triage overhead and make kernel security handling more predictable for maintainers.

