
Reviewed with Claude: About 1 in 5 credit AI help in the commit trailers. What AI was good at: spotting a missing bounds check, a missing lock or a refcount slip in old, rarely audited code. The standouts: - A 2005 IPv6 AH bug (CVE-2026-80844). An unchecked segments_left=255 makes the kernel memmove 4,064 bytes from before its buffer. A code comment claimed it was already verified. Raw packets bypass that check. Sat there ~20 years. - A 2006 RPC GSS client bug (CVE-2026-89541). offset + opaque_len > len can wrap around, so a hostile NFS server gets past the bounds check. - Five BPF verifier fixes credited to Nicholas Carlini. The best one lets a plain allocation into a per-CPU pointer field, which the commit says gives arbitrary kernel read/write. (He has an Anthropic address, so weigh that.) - An NFS-over-RDMA heap overflow (CVE-2026-89530). Replies bigger than a fixed buffer were copied in with no size check. - nfsd refcount bugs a remote NFSv4 client can race, plus SMB client heap overflow and out-of-bounds read bugs that need a malicious server. The caveat: five qdisc fixes look impressive but are one MTU-overflow pattern. One reporter found it, a human maintainer fixed it as a single patch series, and the fixes are only clamps. Not five findings. Reality check: nothing here is unauthenticated remote code execution on a default install. Many of the 1,313 are cosmetic, like a debugfs log message. Recommendation: Good tools, modest findings. Patch anyway.
