Source status: The accepted Linux stable commits explicitly describe Claude Code, Claude review, or Claude Opus 4.6 as finding or pointing out the relevant bug.
Summary
The four accepted fixes document different forms of Claude-assisted review:
- a packet-fanout use-after-free found during an audit with Claude Code;
- an EDAC teardown and ordering bug noticed while Claude reviewed another fix;
- an
nfsdreference leak that Claude pointed out; and - an
amd-pstateleak found with Claude Opus 4.6 and a published AI-review prompt workflow.
Attribution boundary
The kernel commits are direct attribution, but the human contribution remains central: maintainers selected context, reproduced concerns, authored patches, and accepted the fixes.
References
- Linux fix: CVE-2026-31504
- Linux fix: CVE-2026-31689
- Linux fix: CVE-2026-43193
- Linux fix: CVE-2026-53121
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.