Saltar al contenido
ES EN

Linux and open source 2025–2026: what happened and why it matters

Topic guide · Linux and open source

Between August 2025 and August 2026, Linux and open source changed scale. AI multiplied bug reports and forced maintainers to rewrite their rules, kernel flaws and repository attacks reached far, and both Europe and industry answered with strategy and money.

FalconSigned by Falcon, Signals analystUpdated on
45articles analysed
8outlets consulted
Aug 2025 – Aug 2026period covered
23,000potential vulnerabilities flagged by Mythos across more than 1,000 projects
1,579Arch AUR packages affected, at least
$5 billionannounced by IBM and Red Hat for Project Lightwell
Timeline

What happened and when

  1. Linux passes 6% on the desktop

    A Lansweeper analysis of more than 15 million consumer desktops put Linux above 6% share.

  2. Firefox to drop 32-bit Linux

    Mozilla said that in 2026 it will end Firefox support on 32-bit Linux; version 144 will be the last, with ESR 140 as the fallback.

  3. Debian prepares Rust for APT

    Debian plans Rust dependencies in APT from May 2026, to parse packages and verify signatures with memory-safe code.

  4. GNOME bans AI-written extensions

    A new rule forbids submitting Shell extensions built with AI-generated code to extensions.gnome.org, amid a rising flow of such submissions.

  5. AI starts finding real bugs

    Greg Kroah-Hartman said AI review tools went within weeks from unreliable novelty to genuinely useful help in spotting real flaws.

  6. Wine 11 speeds up Windows games

    Wine 11 adds NTSYNC support, which changes how Windows games run on Linux and improves performance.

  7. Linux 7.0 drops Rust's experimental label

    Version 7.0 removes the experimental tag from Rust support and adds post-quantum module signatures; Torvalds calls it a numbering reset.

  8. Cal.com leaves open source

    The scheduling company moves from an AGPL licence to a proprietary one, arguing that AI-equipped attackers exploit public code more effectively.

  9. CopyFail and Dirty Frag shake Linux

    Two privilege-escalation flaws, CopyFail and Dirty Frag, hit major distributions and set off a race to patch.

  10. Torvalds: security list unmanageable

    Linus Torvalds warns that duplicate AI-found reports are swamping the security list; kernel 7.1 documents what counts as a security bug.

  11. IBM and Red Hat launch Project Lightwell

    The two companies announce a $5 billion effort to protect open source ecosystems using AI and more than 20,000 engineers.

  12. EU puts open source at its core

    Its tech sovereignty package gives more than a third of its 29 pages to open source and promises procurement reform.

  13. Over 400 AUR packages, then 1,579

    Packages in Arch's community repository spread an infostealer and an eBPF rootkit; a later count raises the figure to at least 1,579.

  14. Linux Foundation unveils Akrites

    A coalition including AWS, Google, Microsoft and OpenAI creates a shared response team and a maintainer of last resort.

  15. Torvalds defends AI-assisted coding

    In a mailing list post, Torvalds says Linux will not join anti-AI projects and that critics are free to fork.

  16. Debian 13 kernel fixes 68 flaws

    A security update to the 6.12 LTS kernel patches 68 vulnerabilities, against about a dozen in the previous one.

Analysis

The threads that matter

AI enters the kernel and splits communities

Early in 2026 the debate was almost anecdotal: Linus Torvalds admitted using an AI tool for an audio visualizer in a personal project. In March, Greg Kroah-Hartman described a sharp shift: review tools went within weeks from unreliable novelty to a source of good reports, and security teams across several projects saw the same wave at once.

May brought the side effect. Torvalds said the kernel security list had become almost unmanageable because of duplicate reports, and kernel 7.1 documented what deserves treatment as a security bug and that AI-assisted reports are public by default. Around then Torvalds also described a love-hate relationship with AI and commit rates running roughly 20% higher.

Distributions reacted unevenly. GNOME banned AI-generated extensions, Fedora paused its AI developer desktop after community pushback, and Ubuntu users asked for a kill switch for its AI features. In July Torvalds told critics that Linux will not join anti-AI projects and that anyone who disagrees can fork the code.

Kernel flaws and supply chain attacks

A run of local privilege escalations followed in May and June. CopyFail affected practically every version; Dirty Frag, found by Hyunwoo Kim, chains two page-cache write bugs and reached the major distributions; another bug came down to a single misplaced exclamation mark, and an exploit called pedit poisoned the cache of binaries. US agency CISA also added a root-granting Linux flaw to its exploited-vulnerabilities catalog.

Community repositories were the other front. Arch AUR packages delivered an infostealer and an eBPF-based rootkit: first more than 400 packages were reported and later at least 1,579, with Arch conceding its list was incomplete. Reports also covered a hijacked Red Hat namespace on npm, a Quasar trojan aimed at developer credentials, and China-linked intruders said to have tampered with login software for almost a decade.

Infrastructure suffered too: Ubuntu and Canonical were offline for more than 24 hours after a DDoS attack in the middle of a security incident. In August, Debian 13 received a kernel update with 68 fixes, when the previous one had resolved only a dozen.

The defensive response: money, coordination and Rust

Industry answered with big numbers. Anthropic said its Mythos model flagged 23,000 potential vulnerabilities across more than 1,000 open source projects; IBM and Red Hat announced Project Lightwell, worth $5 billion and backed by more than 20,000 engineers; and the Linux Foundation unveiled Akrites, with a shared response team and a maintainer of last resort for abandoned packages.

Rust is the other lever. Kroah-Hartman argues the language prevents the typical C mistakes, which account for around 60% of kernel vulnerabilities. Linux 7.0 dropped Rust's experimental label, and Debian had already announced that APT will depend on Rust from May 2026 to parse archives and verify signatures.

There is also a sustainability problem: a Linux Foundation working group is studying how to fund and govern package registries swamped by automated traffic, and Sonatype's Brian Fox estimates 10 trillion downloads in 2025.

Desktop, gaming and compatibility

Linux advanced where usage is measured. Lansweeper put its desktop share above 6% using data from more than 15 million machines, and Phoronix data on Steam showed 5.33% one month and 4.52% the next, against 2.27% a year earlier: more than double. Wine 11 and its NTSYNC support rewrite how Windows games run, with notable performance gains.

The application ecosystem is reshuffling too. Mozilla will drop Firefox for 32-bit Linux in 2026, with version 144 as the last and ESR 140 as the fallback; GIMP now ships its own Snap package, built from its CI pipeline instead of relying on Snapcrafters; and T2 SDE launches a desktop ready for daily use after a decade focused on embedded systems and servers.

Policy and licensing: sovereignty, age checks and AI

In June the European Union put open source at the centre of its tech sovereignty package: more than a third of the 29 pages deals with it, with procurement reform, the principle of public money, public code, and the aim of relying less on non-EU providers.

Age-verification laws opened another front: distributions such as Ubuntu, Fedora and Mint, together with System76 and the EFF, debated how to respond, and Colorado amended its bill to exempt open source software.

AI also presses on licensing. Cal.com moved from AGPL to a proprietary licence, arguing that AI-equipped attackers exploit public code more effectively, and two researchers showed, partly as satire, how to reproduce open projects in minutes as seemingly distinct versions, which strains clean-room reverse engineering.

What it means

Why it matters and what to watch

Triage is the new bottleneck

Finding bugs is no longer the scarce part; people who filter duplicates and decide what is truly a security problem are, as kernel 7.1 and Akrites show.

Community repositories are the weak link

The AUR and npm attacks suggest that trust in packages without strong review is the risk to watch, more than the kernel itself.

Memory-safe languages gain ground

Rust is no longer an experiment in the kernel or in APT; watch whether it measurably cuts the class of bugs that now fill the advisories.

Openness is being argued as a business model

Cal.com's exit set against European backing shows two opposite readings of open source in the age of AI.

Our view

What we think

We read this period as a signal about where pressure is moving, not as a crisis of the kernel itself. The sharpest signal is that finding flaws has become cheap while judging them has not: maintainers, not scanners, are now the constrained resource. The kernel's answer, clear rules and human judgement, looks like the template others will copy. The weaker signal worth watching sits in community repositories, where trust is inherited rather than checked. We understand projects that close their code out of fear, but we think the trade is poor. Transparency still beats secrecy wherever someone funds the watching. Backing maintainers will matter more than buying detectors.
Falcon, Signals analyst
Archive articles

Everything we published on this topic

45 stories from Aug 2025 to Aug 2026, by month. These are the original articles this guide rests on; each one links to its source.

August 2026 · 1 article
July 2026 · 1 article
June 2026 · 11 articles
May 2026 · 15 articles
April 2026 · 6 articles
March 2026 · 5 articles
January 2026 · 1 article
December 2025 · 1 article
November 2025 · 1 article
October 2025 · 1 article
September 2025 · 1 article
August 2025 · 1 article
Keep reading

Related guides

This guide synthesises 45 stories published on La Rebelión between Aug 2025 and Aug 2026. It is written with AI assistance and editorial review, following the process described in Editorial process.