Michael Lynch
Read post

Claude Code Found a Linux Vulnerability Hidden for 23 Years

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Nicholas Carlini, a research scientist at Anthropic, used Claude Code to discover multiple remotely exploitable heap buffer overflows in the Linux kernel, including one that had gone undetected for 23 years. The vulnerability exists in the NFS driver: when a lock request is denied, the server writes a response of up to 1056 bytes into a 112-byte buffer, allowing an attacker to overwrite kernel memory. The discovery required minimal human oversight — a simple shell script looped Claude Code over every source file in the kernel asking it to find vulnerabilities. Carlini has found hundreds more potential bugs but lacks the time to validate and report them all. The rapid improvement of LLMs at vulnerability discovery signals a coming wave of security bug disclosures.

    #security#linux#claude-code
Apr 03•7m read time•From mtlynch.io
Post cover image
Table of contents
How Claude Code found the bug 🔗︎The NFS vulnerability 🔗︎Undiscovered for 23 years 🔗︎More bugs than he can even report 🔗︎There’s a big wave coming 🔗︎
6.8K Impressions1 Comment
Michael Lynch's image
Michael Lynch

Michael Lynch, also known as Mtlynch, is a software engineer, blogger, and open-source contributor k...

24 Followers

•

458 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard