FR
live
AI

Google’s Sashiko AI has reviewed 191,000 Linux kernel patches and is cited in 463 CVEs in one year

At Linux Plumbers Conference 2026, Google detailed Sashiko, its agentic code-review system for the Linux kernel: 191,000 patches reviewed across 99 lists, and 1,277 upstream commits and 463 CVEs citing it in one year. Those numbers make automated review a credible complement for overloaded maintainers — not a replacement.

A jeweler’s loupe resting on a dark printed circuit board, one amber copper trace among hundreds of grey traces.

October 2026. At the Linux Plumbers Conference, Roman Gushchin of Google’s kernel team detailed the results of Sashiko, its agentic AI code-review system. 191,000 patches reviewed in under a year. 463 kernel CVEs citing it in 2026. 53% of bugs caught in a sample of 1,000 fixes — all of them missed by human reviewers. Why it matters: kernel code review is a bottleneck, and these numbers are the first public measurement of what an AI can absorb.

What Sashiko actually does

Sashiko is a code-review agent built for the Linux kernel. It does not generate patches: it reads every submission arriving on the kernel mailing lists and produces a review report for maintainers. The project is open source on GitHub, funded by Google — which pays the token budget and infrastructure — and its hosting is moving to the Linux Foundation.

The agent was designed for Gemini 3.1 Pro, but it also works with Claude and other LLMs. The public interface lives at Sashiko.dev. Inside Google, it had been running for months before the public release, covering all submissions to LKML.

The telling detail: measuring an unfiltered sample of 1,000 recent upstream kernel fixes carrying a “Fixes:” tag, Sashiko recovered 53% of the bugs they fixed. The follow-up is more striking still — 100% of those bugs had been missed by human reviewers. Gushchin preempts the objection: “Some might say that 53% is not that impressive, but 100% of these issues were missed by human reviewers.”

Metrics that actually count

The results presented at the conference are remarkable for their precision, where most AI projects settle for demos.

  • 191,000 patch reviews completed in under a year, across 99 different mailing lists.
  • 19 million autonomous Git lookups, made by the agent to recontextualize each patch.
  • 7,600 replies received from more than 1,100 kernel developers in response to Sashiko reports.
  • 1,277 commits in the upstream kernel citing Sashiko this year, and 1,567 in linux-next.
  • 463 kernel CVEs citing Sashiko since the start of the year.

The last two numbers are the most important. A commit that “cites” Sashiko means an accepted kernel fix references a review from the agent — in other words, the tool directly contributed to the fix. The fact that 463 CVEs are attributed to it moves the debate: this is no longer a promise, but real security fixes that might not have been found as fast.

Why this changes the calculus for the kernel

The Linux kernel receives thousands of submissions per development cycle, and the number of maintainers able to review them seriously has not kept up. The consequence is well known: fixes sit for weeks awaiting review, and bugs slip through because a busy reviewer never had time to follow a thread.

That is where Sashiko steps in. It does not replace the maintainer — it pre-reads, flags, asks the right questions, and leaves the human to decide. The 19 million Git lookups are revealing: a large share of review work is recontextualizing a patch in the code’s history, which is slow and mechanical. An agent doing that in the background makes every maintainer faster on the part that demands judgment.

The context gives this report a particular flavor. A week earlier, Greg Kroah-Hartman dismantled AI-generated security reports by showing that much of it was noise. Sashiko is the other side of the coin: a dedicated AI, wired into the real kernel flow, whose impact is measured in commits and CVEs, not detached reports.

The limits, to keep from getting carried away

The 53% figure deserves a careful reading. It does not say Sashiko finds 53% of all kernel bugs: it says that, on a sample of already-written fixes, the agent recovered a little over half of the causes. That is a measure of recall on known bugs, not coverage of unknown bugs. A bug nobody has found and fixed yet does not enter the sample.

Second limit: the agent proposes, the maintainer disposes. The 1,277 commits citing Sashiko are the result of a human deciding the review was relevant. Nothing in this report suggests an AI review could be merged without human oversight — and that is precisely what makes the number credible.

Finally, Google is still building the roadmap: a local terminal review mode, a persistent bug database, and even self-review where Sashiko reviews its own code. All of which confirm the tool is a long-term investment, not a PR moment.

What other projects can take from it

The Linux kernel is a favorable edge case: a huge submission flow, a rich code history, and maintainers able to validate what the agent proposes. The question is whether the lessons transfer to smaller projects.

Part of it, yes. The core principle — wiring the agent into the real flow rather than asking it for detached reports — applies everywhere. It is the difference between an AI that reviews your pull requests as they land and an AI that generates security audits from a general model. The second produces noise; the first produces reviews that real developers can accept or reject.

Another lesson is measurement. Google does not talk about “quality” in the abstract: it publishes the number of reviews, citing commits and CVEs. That is what makes the results credible, and it is what most AI deployments in product teams lack — a baseline number before the tool, and the same number after.

The limit is the available signal. A project with a rich code history and documented bugs gives the agent material to learn what an anomaly looks like. A young project, with no corpus of labeled fixes, will struggle — the agent has nothing to recontextualize against. Sashiko does not replace that raw material; it exploits it.

The kernel’s scale also means Sashiko enjoys a luxury most teams lack: a firehose of reviewable changes. Its value is proportional to the volume of real code it can see, which is why wiring an agent into the live flow matters more than any model choice. That, more than the specific LLM, is the transferable lesson.

Verdict

If you maintain a project with a review bottleneck, the Sashiko example is the strongest evidence to date that an agentic AI wired into the real flow can absorb the mechanical share of the work — pre-reading, recontextualization, flagging — and that its impact is measured in commits and CVEs, not promises. If you expect AI to replace your reviewers, the limits remain clear: 53% recall on already-fixed bugs, and every merge is still a human decision. The lesson for product teams: scope the agent to a precise perimeter, wire it to your real data, and measure its contribution in merged fixes rather than demos — that is exactly the difference between Sashiko and the noise that gave skeptics their arguments.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Mistral opens Large 4, a 1.05-trillion-parameter model whose weights land at the end of October

On October 6, 2026, Mistral AI shipped a public preview of Mistral Large 4, nicknamed “Le Chonk”: a multimodal mixture-of-experts model of roughly 1.05 trillion parameters, 49 billion active per token, with open weights promised for October 27. Test it on your own workloads now, but withhold any judgment on the benchmarks until the weights and the license are actually published.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss