All findings

CVE-2026-31504 + 3 more high

Linux fixes explicitly credit Claude-assisted review across four CVEs

Upstream Linux fixes describe Claude Code or Claude model review surfacing four security bugs in packet sockets, EDAC, nfsd, and amd-pstate.

Bug class
Use-after-free, ordering failure, and kernel resource leaks
Affected codebase
Linux kernel networking, EDAC, NFS, and amd-pstate
Credited system
Claude / Anthropic Research
Disclosed
June 24, 2026
Attribution
Direct source attribution
Severity
high
Source status: The accepted Linux stable commits explicitly describe Claude Code, Claude review, or Claude Opus 4.6 as finding or pointing out the relevant bug.

Summary

The four accepted fixes document different forms of Claude-assisted review:

Attribution boundary

The kernel commits are direct attribution, but the human contribution remains central: maintainers selected context, reproduced concerns, authored patches, and accepted the fixes.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.