Greg Kroah-Hartman on security in the LLM era (video)
google
| Source: HN | Original article
Greg Kroah‑Hartman addresses security in the LLM age in a new video.
Greg Kroah‑Hartman, the Linux Foundation fellow who shepherds the stable kernel, has released a short video that pulls back the curtain on how large language models are being used to hunt for kernel vulnerabilities. In the clip, posted on Hacker News three days ago, Kroah‑Hartman explains that a closed‑source “frontier++” model was tasked with scanning past kernel patches and surfaced 37 of the 76 CVEs that later appeared in a public “Mythos” analysis.
The demonstration matters because it shows AI‑driven tools can replicate, and in some cases surpass, human‑led code review in spotting security flaws. By pattern‑matching decades of kernel commit history, the model identified gaps that had already been patched, suggesting a route for automated verification of whether fixes have been universally applied. Kroah‑Hartman also points out that the Mythos report, which claimed 79 CVEs, failed to credit the kernel developers who originally fixed them—a reminder that AI‑generated research still needs rigorous attribution and human oversight.
The video arrives amid growing concern over AI agents’ elevated privileges, echoing Apple’s recent move to tighten “Full Disk Access” controls on macOS for similar risk reasons. As the Linux community watches, the next steps will likely involve evaluating the reliability of LLM‑based vulnerability scanners, establishing guidelines for crediting original authors, and possibly integrating AI checks into the kernel’s review pipeline. Stakeholders will also be keen to see whether LLM providers respond with more transparent model disclosures or tools tailored for open‑source security auditing.
Sources
Back to AIPULSEN