What it is
This profile groups public Linux kernel discoveries made with Gemini CLI or experimental review agents based on Gemini 3.1 Pro. The workflows vary: one operator asked Gemini to diagnose an Android Binder bug, while later review agents raised concerns on submitted patches that maintainers then verified.
What is verified
Four upstream stable commits explicitly describe Gemini’s discovery or review role: CVE-2026-23194, CVE-2026-23309, CVE-2026-31552, and CVE-2026-43067. The commits are both the attribution source and the accepted-fix record.
Attribution boundary
These are not claims that Gemini autonomously shipped kernel patches. Human contributors selected code or patches, verified the reports, and authored the accepted fixes. Bugflation records the narrower, publicly documented review contribution.