Using LLM-Based Verification to Eliminate Bugs in Linux's Network Stack
Researchers used large language models to assist in formally verifying the Linux nftables firewall compiler and optimizer. In the process they discovered and patched two critical bugs that had existed in the kernel since 2022. The work demonstrates that LLM‑guided verification can make the creation of provably correct networking software increasingly practical.
- ▪The team applied LLMs to guide proof construction in the Rocq theorem prover for the nftables CLI tool.
- ▪Two semantics‑altering bugs affecting all Linux versions since 2022 were identified and disclosed to maintainers.
- ▪The verified implementation was shown to be free of these bugs, and a naive LLM bug search would have missed the more severe one.
- ▪The experiments suggest that the effort required for formal verification of critical infrastructure can be increasingly automated.
Hacker News (AI / LLM) files mainly under ai. We currently carry 3,301 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Basis |
| Canonical URL | https://www.basis.ai/blog/verified-nftables/ |
| Publication time | Mon, 20 Jul 2026 13:52:06 +0000 |
| Retrieval time | 2026-07-20T15:26:58.965Z |
| Last seen | 2026-07-20T15:26:58.965Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | PVjgYTGykjng |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Using LLM-based Verification to Eliminate Bugs in Linux's Network StackArticle: Yiyun Liu, Kiran Gopinathan, Nikhil PimpalkhareResearch: Yiyun LiuWe used LLMs to verify Linux's nftables `nft` CLI utility. Along the way, we found and patched bugs that had sat in the kernel for years.Firewall rules act like railway signals, telling each packet whether it may pass.LLMs have grown alarmingly capable at finding bugs in production software. This accentuates an already severe risk: much of our critical infrastructure is mediated by software, and every bug in that software is a potential exploit.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Basis.