Greg Kroah-Hartman: Mythos's 79 Linux kernel bugs came down to 10 real fixes and one hour of work
- In his Kernel Recipes 2026 talk, Greg Kroah-Hartman broke down Mythos's 79 reported Linux kernel vulnerabilities: 24 had no detail beyond "something crashed", 14 were not bugs at all, 3 were made up, 15 were already fixed in the latest release, and 20 needed fixes. The numbers only add to 76, which he mocked in the video.
- Kroah-Hartman called the result about 10 real bugfixes, and said the whole thing boiled down to roughly one hour of kernel development work.
- At 3m19s he said Mythos was doing pure pattern matching over decades of kernel developer patches and applying those mechanisms elsewhere, and that Anthropic did not credit the kernel developers who originally fixed those CVEs.
- Curl maintainer Daniel Stenberg wrote a post calling the Mythos curl finding a marketing stunt; commenters point to AISLE as getting more real issues out of LLMs, suggesting the advantage may not be the frontier model itself.
- Commenters argue bug counts from automated scanning are mostly false positives that take hours of expert triage, and one notes the NFS heap overflow CVE-2026-31402 came from Claude Code, not Mythos, while another counters that the time to fix says nothing about severity.
Hacker News opinions
The slide breakdown is brutal. 24 of the 79 had no detail at all beyond "something crashed", 14 weren't bugs, 3 were made up, 15 were already fixed in the latest release. He counted 10 real bugfixes and then made fun of the fact that his own numbers only add to 76.
We've been on the receiving end of this in smaller repos we manage security for. Automated scans mostly produce verbose nonsense that takes hours of expert time to test and discard, and a Claude false positive is excruciating because it is absolutely sure of itself, with pages of wild proof-of-concept code attached.
Same as the CVEs scanners hand out at places I've worked. Bug count alone was never the point, and I do remember an NFS bug and a kernel bug in the Anthropic paper being genuinely interesting. Turns out the NFS heap overflow, CVE-2026-31402, was found by Claude Code months earlier, not Mythos.
At 3m19s he says Mythos just pattern matched decades of kernel patches and applied the same mechanisms elsewhere to see what was still unpatched. And Anthropic didn't cite the developers who fixed the originals, which is the least you'd expect.
It all came down to one hour of kernel development work. Sam Altman said GPT-3 was too scary to release, and now a 79-bug press release collapses into an hour of fixes. That dissonance makes every future announcement easier to doubt.
Time to fix has no correlation with severity, so that's not the headline here. The headline is that none of the bugs were serious.
His style is no-nonsense but I want him to explain how it's "only 10 real bugs" when over 1300 CVEs went out last month. Not much counts as a real bug when an LLM finds it, but anything goes when it's time to push distros onto an LTS release.
Mythos may be weak today, but a model trained on kernel specifics, coding standards, threat models and good and bad patch patterns could be relentless and worth the electricity. Pair it with a second model trained on triage data to validate the first, which I think Microsoft is doing internally.
Daniel Stenberg wrote up the curl find and it was exactly the marketing stunt it smelled like. AISLE seems to get more actual issues out of LLMs, whatever they do differently, so the secret sauce probably isn't the frontier model being exceptionally powerful.
The off-topic flag on this submission is my favorite part. Apparently Anthropic escaping containment is what hackers are curious about, and the Linux kernel is not.