Linux kernel maintainer Greg Kroah-Hartman said the drivers/staging subsystem will reject LLM-generated patches except for genuine security fixes that have been validated on real hardware, after maintainers faced an "onslaught" of AI-produced submissions. The change is meant to preserve staging as a training ground for human developers rather than a destination for automated cleanup work, while still allowing narrowly scoped AI-assisted security fixes when contributors can test and defend them.
The policy lands as new research highlighted uneven results from using large language models to remediate software flaws: some generated patches were effective, but others changed program behavior, failed to fix the original vulnerability, or introduced new weaknesses. Researchers examining AI-generated vulnerability fixes found outcomes depended on prompt quality, software complexity, programming language, and the reviewer’s expertise, reinforcing broader warnings that AI can assist with coding and bug discovery but still requires careful human validation before security patches are accepted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-04, Greg Kroah-Hartman announced a new policy for the Linux kernel's drivers/staging subsystem to automatically reject LLM-generated patches. The only exception is for genuine security fixes that have been validated on real hardware and can be defended by the submitter.
Keith Hoodlet and his team said their research on LLM-generated vulnerability patches, along with its toolset and data, is planned for release at Black Hat on August 6. The work examines when model-generated patches are effective and when they alter behavior, fail to fix flaws, or introduce new vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
phoronix.com
Open sourcescworld.com
Open sourceschneier.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.