All systems

Google and Linux kernel contributors AI agent

Google Gemini security review agents

Gemini CLI and experimental Gemini review agents with explicit discovery credits in accepted Linux kernel fixes.

1
Indexed entries
4
CVE IDs tracked
1
Critical/high entries
96%
Evidence index

What it is

This profile groups public Linux kernel discoveries made with Gemini CLI or experimental review agents based on Gemini 3.1 Pro. The workflows vary: one operator asked Gemini to diagnose an Android Binder bug, while later review agents raised concerns on submitted patches that maintainers then verified.

What is verified

Four upstream stable commits explicitly describe Gemini’s discovery or review role: CVE-2026-23194, CVE-2026-23309, CVE-2026-31552, and CVE-2026-43067. The commits are both the attribution source and the accepted-fix record.

Attribution boundary

These are not claims that Gemini autonomously shipped kernel patches. Human contributors selected code or patches, verified the reports, and authored the accepted fixes. Bugflation records the narrower, publicly documented review contribution.

Sources

Attributed findings

Catalogued entries credited to Google Gemini security review agents.