Source status: The Linux CNA descriptions and accepted fix records explicitly state that Atuin discovered the flaws. CVE.org provides the public identifiers and upstream references.
Summary
The three Linux records cover a USB-storage heap-corruption path, an out-of-bounds access in the CH341 SPI driver, and a NULL dereference in the legacy applicom driver.
Attribution
The public Linux CNA descriptions explicitly use discovery language naming Atuin. That is stronger than attributing AI use from the reporter’s laboratory alone.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.