Live data from Hacker News

Claude Code Found a Linux Vulnerability Hidden for 23 Years

mtlynch.io

111–120 of 303 posts

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#111
post #68

Earlier quoted context omitted.

The lesson here shouldn't be that Claude Code is useless, but that it's a powerful tool in the hands of the right people.

The same could be said about a Roulette wheel set before a seasoned gambler

This is a non-sequitur if I ever saw one.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#112
post #47
post #33

Earlier quoted context omitted.

> What is not mentioned is that Claude Code also found one thousand false positive bugs, which developers spent three months to rule out. Source? I haven't seen this anywhere. In my experience, false positive rate on vulnerabilities with Claude Opus 4.6 is well below 20%.

In TFA: I have so many bugs in the Linux kernel that I can’t report because I haven’t validated them yet… I’m not going to send [the Linux kernel maintainers] potential slop, but this means I now have several hundred crashes that they haven’t seen because I haven’t had time to check them. —Nicholas Carlini, speaking at [un]prompted 2026

The comment said "Claude Code also found one thousand false positive bugs, which developers spent three months to rule out.".

Please explain how a bug can both be unvalidated, and also have undergone a three month process to determine it is a false positive?

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#113
post #49

Earlier quoted context omitted.

Those aren't false positives; they're results he hasn't yet inspected. I wrote a longer reply here: https://news.ycombinator.com/item?id=47638062

> Those aren't false positives; they're results he hasn't yet inspected. It's not a XOR

The article quote was being given as the supposed source for "Claude Code also found one thousand false positive bugs, which developers spent three months to rule out", so should substantiate that claim - which it doesn't.

If the claim was instead just "a good portion of the hundreds more potential bugs it found might be false positives", then sure.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#115

This isn't surprising. What is not mentioned is that Claude Code also found one thousand false positive bugs, which developers spent three months to rule out.

That's not what is happening right now. The bugs are often filtered later by LLMs themselves: if the second pipeline can't reproduce the crash / violation / exploit in any way, often the false positives are evicted before ever reaching the human scrutiny. Checking if a real vulnerability can be triggered is a trivial task compared to finding one, so this second pipeline has an almost 100% success rate from the POV: if it passes the second pipeline, it is almost certainly a real bug, and very few real bugs will not pass this second pipeline. It does not matter how much LLMs advance, people ideologically against them will always deny they have an enormous amount of usefulness. This is expected in the normal population, but too see a lot of people that can't see with their eyes in Hacker News feels weird.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#116

Earlier quoted context omitted.

No, they haven't. Read the ai slop you posted carefully. It's a policy update that enables maintainers to ignore low effort "contributions" that come from untrusted people in order to reduce reviewing workload. An Eternal September problem, kind of.

Didn't you just restate what the parent claimed?

No, that's not at all the same thing: ai-generated contributions from people with a track record for useful contributions are still accepted.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#117

Earlier quoted context omitted.

Claude and Codex pro/max subs aren't supposed to be used for commercial/enterprise development so its not really an option for execs in enterprise. They need to take into account API costs. At my F500 company execs are very wary of the costs of most of these tools and its always top of mind. We have dashboards and gather tons of internal metrics on which tools devs are using and how much they are costing.

> Claude and Codex pro/max subs aren't supposed to be used for commercial/enterprise development lolwut?

Read ToS.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#119
post #116

Earlier quoted context omitted.

Didn't you just restate what the parent claimed?

No, that's not at all the same thing: ai-generated contributions from people with a track record for useful contributions are still accepted.

Right. AI submissions are so burdensome that they have had to refuse them from all except a small set of known contributors.

The fact that there’s a small carve out for a specific set of contributors in no way disputes what Supermancho claimed.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#120
post #68

Earlier quoted context omitted.

The lesson here shouldn't be that Claude Code is useless, but that it's a powerful tool in the hands of the right people.

The same could be said about a Roulette wheel set before a seasoned gambler

No. The seasoned gambler can not learn things that measurably increase their chance at the Roulette, whereas they definitely can do that with an LLM. And the LLM itself becomes smarter over time through hardware upgrades, software updates and even memory for those who enable that feature.
Post reply on HN