All findings

CVE-2026-23194 + 3 more high

Gemini CLI and review agents surface four Linux kernel CVEs

Linux stable commits explicitly credit Gemini CLI or experimental Gemini 3.1 Pro review agents on four accepted security fixes.

Bug class
Out-of-bounds access, NULL dereference, infinite loop, and allocation wraparound
Affected codebase
Linux Android Binder, tracing, wlcore, and ext4
Credited system
Google Gemini security review agents
Disclosed
May 20, 2026
Attribution
Direct source attribution
Severity
high
Source status: Each accepted Linux stable commit names Gemini CLI or the Gemini-based review agent and explains the concern the model raised.

Summary

The first entry records Gemini CLI diagnosing an out-of-bounds Android Binder condition from an operator prompt. The other fixes document an experimental Gemini 3.1 Pro review agent raising concerns in tracing, wireless-driver, and ext4 patches that contributors then verified.

The cluster demonstrates code review rather than a fully autonomous audit. It is still direct upstream evidence that named AI review workflows surfaced security-relevant bugs accepted by kernel maintainers.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.