agentusecasesAll 965 use cases
Security, Science & Hardware

Find a Linux vulnerability hidden for 23 years

An account of Claude Code uncovering a long-standing vulnerability in Linux.

Done withClaude Code

What they did
Nicholas Carlini, a research scientist at Anthropic, ran a short script that looped over every file in the Linux kernel source. For each file, it told Claude Code it was in a CTF, hinted the bug was in that file, and asked it to write its most serious finding to an output directory. Humans then had to validate the results.
How it went
Claude Opus 4.6 found several remotely exploitable kernel bugs, including an NFS heap overflow from 2003. Five fixed or reported vulnerabilities are listed. Older models found only a small fraction of these.
Worth knowing
Validating the findings by hand is the bottleneck: Carlini has several hundred unreviewed crashes. He won't send maintainers unverified reports, so most findings are still unreported.

Try it yourself with Claude Code

In my local checkout of [open-source project or kernel subsystem] at [path], review the code in [directory or module] for memory-safety or logic bugs that could be security vulnerabilities. For each suspected issue, give the file, line, why it's a problem, and how to confirm it safely in a test environment. Finished means a ranked list of findings, and don't make changes or report anything publicly without asking me.

Read the original ↗

Discussion on HN · Apr 3, 2026

Five of these in your inbox every morning

The best things people got an AI agent to do, each with the prompt to try it.

More like this