Greg Kroah-Hartman reportedly discussed the rise in AI-generated security reports and the need for disciplined triage on October 1, 2026. The remarks put a practical distinction in focus: Sashiko reviews proposed Linux kernel changes, while XBOW describes a separate investigation of CVE-2026-72018.

AI-generated security reports put triage in focus

For kernel maintainers, an AI-generated report is a lead to assess, not a substitute for reviewing a proposed change or investigating a suspected flaw. The work described under Sashiko and the CVE-2026-72018 investigation illustrates two different roles for automation, with human judgment involved in both.

What Sashiko reviews in the Linux kernel

Greg Kroah-Hartman Reportedly Addressed AI Security Reports

Sashiko is an agentic system that monitors public mailing lists and reviews proposed Linux kernel changes. Its specialized reviewer roles cover areas including security, architecture, resource management, and concurrency, using a multi-stage review process with general and subsystem-specific prompts. It reviews code changes; it is not a security control running inside the kernel.

Sashiko describes the open-source project as part of the Linux Foundation and says it uses the Apache License 2.0. The project also says Google funds the service’s computing resources and large-language-model tokens.

In July 2026, Sashiko v0.2.5 added initial support for Linux media-subsystem patches. A cautious trial routed reports to the media-CI mailing list and Patchwork for contributors to review, including for false positives. Local use with Ollama was also described for that integration, with an estimated 10–20 minutes per patch.

CVE-2026-72018 was a separate investigation

The National Vulnerability Database describes CVE-2026-72018 as an out-of-bounds write in the Linux kernel’s loopback DIBS implementation. In move_data(), the code copied data into a registered Direct Memory Buffer without checking whether the offset and write size exceeded the buffer’s length. The fix adds a bounds check and rejects invalid requests with -EINVAL.

XBOW says its researchers found and validated the vulnerability, then developed a proof of concept. In a report dated September 28, 2026, XBOW said the exploit succeeded in 22 of 100 separate boots of Ubuntu 24.04 running Linux 7.1.0-rc6/x86_64, with all kernel mitigations disabled. That result belongs to those laboratory conditions.

The NVD version table identifies Linux 6.10 as affected and lists 6.12.97, 6.18.40, and 7.1.5 as unaffected entries for their respective branches; it also lists versions below 6.10 as unaffected. Linux distributions can backport fixes, so the upstream version entries do not determine the status of every vendor kernel. The NVD record displays a CVSS 3.1 score of 7.8 (High) from kernel.org’s CNA.

Human researchers redirected parts of XBOW’s work

XBOW says human researchers intervened at three points: they redirected the investigation toward packet interception, asked for experimental measurement of the write behavior, and focused the work on an available zero-write. These were decisions within that particular research campaign, not measurements of Sashiko’s performance.

The distinction is practical. Sashiko examines proposed changes arriving through mailing lists; XBOW’s account concerns investigating a flaw in existing kernel code and developing a proof of concept. For a specific Linux distribution, the relevant next step is to check its own advisory for CVE-2026-72018 and any backported fix.