Find a Linux vulnerability hidden for 23 years
An account of Claude Code uncovering a long-standing vulnerability in Linux.
Done withClaude Code
- What they did
- Nicholas Carlini, a research scientist at Anthropic, ran a short script that looped over every file in the Linux kernel source. For each file, it told Claude Code it was in a CTF, hinted the bug was in that file, and asked it to write its most serious finding to an output directory. Humans then had to validate the results.
- How it went
- Claude Opus 4.6 found several remotely exploitable kernel bugs, including an NFS heap overflow from 2003. Five fixed or reported vulnerabilities are listed. Older models found only a small fraction of these.
- Worth knowing
- Validating the findings by hand is the bottleneck: Carlini has several hundred unreviewed crashes. He won't send maintainers unverified reports, so most findings are still unreported.
Try it yourself with Claude Code
In my local checkout of [open-source project or kernel subsystem] at [path], review the code in [directory or module] for memory-safety or logic bugs that could be security vulnerabilities. For each suspected issue, give the file, line, why it's a problem, and how to confirm it safely in a test environment. Finished means a ranked list of findings, and don't make changes or report anything publicly without asking me.
Discussion on HN · Apr 3, 2026
Five of these in your inbox every morning
The best things people got an AI agent to do, each with the prompt to try it.
More like this
Turn tickets into merged pull requests
Pulls tasks from GitHub Issues or Linear, then runs Claude Code or Codex in isolated Kubernetes pods to carry each one through to a PR.
Manage an inbox and build courses and budgets with Claude Code
A non-technical user filters their inbox to emails needing replies, turned 15 homeschool PDFs into interactive narrated courses, and built a budget dashboard.
Build a 2D platformer game without coding
A content creator with no coding experience used Claude Code to build a black-and-white wave-combat platformer in HTML canvas and played it live.
- Claude
Find exploitable bugs in smart contracts
Anthropic's red team reports agents finding $4.6M worth of blockchain smart contract exploits.
Control and calibrate a robotic hand with OpenClaw
An OpenClaw agent running Claude drove a 16-joint printed hand, checked its actions with a USB camera, calibrated firmware and narrated in Telegram.
Find security flaws in open-source software
Google's Big Sleep agent reported about 20 security flaws in open-source software, following its SQLite find.