Security issues on Linux — page 2
Issues the maintainers labelled both platform:linux and area:security.
752 issues · 249 open · 503 resolved (67%) · first seen May 20, 2025
Is this getting better or worse?
This class of problem is still growing. 581 new reports in the last 90 days vs 45 in the 90 before — +1191%. The open backlog peaked at 381 in 2026-07 and sits at 249 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
162 of these reports name the Claude Code build they were running, spanning 90 releases. Heaviest reporters:
- Claude Code v2.0.76
- Claude Code v2.1.207
- Claude Code v2.1.206
- Claude Code v2.1.201
- Claude Code v2.1.247
- Claude Code v2.1.241
- Claude Code v2.1.234
- Claude Code v2.1.198
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 46 days across 503 closures. Of the 503 closures with a recorded reason, 10% were closed as completed and 451 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
52 of these issues post a workaround someone says worked. The highest-engagement ones:
- bypassPermissions mode not working in VS Code extension
- issue was reproduced on after upgrade IDE-VSCODE-CC-01-v1: Workaround — bypassPermissions in VSCode Extension Linked rule: [IDE-VSCODE-CC-01-v1](IDE-VSCODE-CC-01-v1.md) Upstream: [anthropics/claude-code 20536]( --- Envir…
Found in the thread of #20536 · still open - [BUG] Linux sandbox broken - bad bwrap calls and no allow permissions
- …ect root instead of protecting .git/HEAD, .git/config, etc. Workaround Added rooted patterns to .gitignore: /HEAD /config /hooks /objects /refs /.bash profile /.bashrc /.profile /.zprofile /.zshrc /.gitconfig /.gitmodule…
Found in the thread of #17727 · still open - [BUG] .claudeignore not ignoring private files
- …oses such as software testing or inter agent documentation. Workarounds to this scenario include changing while the agents are working and restoring it when doing git operations, or allowing agents to ignore which leads…
Found in the thread of #16704 · resolved - [BUG] ask list is ignored when "Bash" is in allow list
- …ands) and safety (protection against destructive commands). Workarounds attempted (none work) : - - Bypasses everything including ask list - - Prompts for every new command type
Found in the description of #6527 · still open - [FEATURE] GPU device passthrough in sandbox mode
- I did end up with a workaround, but this would be a really good feature to support natively so trickery is not required. 1. Ensure ~/.local/bin/ is on your PATH before /usr/bin 2. Make ~/.local/bin/bwrap: 3. Relaunch cla…
Found in the thread of #13108 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 101–200
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 752 matches; the statistics above cover all 752.
- [Bug][cyber] Safety block on command catalog analysis during drone firmware reverse-engineering (req_011CcUWtZavjwra9FL2V6m6b)
- [Bug][cyber] Safety block on documenting drone SDK video relay architecture using RTP/UDP (req_011CcUVFUHna4D2Xe8Baq8ki)
- [Bug][cyber] Firmware reverse-engineering on owned hardware blocked as cybersecurity violation (req_011CcUAjRa9PvvVGm8RG9SH3)
- [Bug][cyber] Downloading and statically analyzing consumer drone firmware revision blocked as unsafe (req_011CcUAhjiFQdPmb12cvvES7)
- [Bug][cyber] USB drone ADB property queries for firmware ID blocked as cybersecurity violation (req_011CcUFxiBU3YjJ8m5A96zMM)
- [Bug][cyber] SSH key enumeration in shell script blocked during IoT device USB debugging session (req_011CcUFvuCT143N2ESjqDEQi)
- [Bug][cyber] Safety block stops download of official vendor firmware for defensive hardening (req_011CcUEhx38FW651McusGmnL)
- [Bug][cyber] ClAudit false-positive in DJI — req_011CcUCoXHXhVnD1FVWiQuqJ
- [Bug][cyber] IAM admin blocked from auditing/correcting cloud directory group membership against active mailbo (req_011CcHRT5uU7bzxr2HFNXbpM)
- [Bug][cyber] ClAudit false-positive
- [BUG] Empty server-managed settings (304 cached) zero out local managed-settings.json — deny/allow rules never enforced
- [Bug] Fable 5 safety classifier false-positive on defensive security code triggers unwanted Opus 4.8 fallback
- [FEATURE] DISABLE_NONESSENTIAL_TRAFFIC silently disables security updates — unbundle DISABLE_AUTOUPDATER
- Feature Request: Documented opt-out for built-in default-branch push guard (CLI)
- [BUG] Heredoc as first argument bypasses pipe target permission checks
- Model reasons past PreToolUse deny based on conversation context (semantic bypass)
- Security: Claude Code exposed .env with private key via http.server, resulting in $1,324 theft
- [Opus 4.6] Claude Code deleted all personal files with find / -delete during security test execution
- [Bug] Plan mode missing permission prompt for destructive rm command
- [BUG] Claude Code fails with EACCES on multi-user systems when /tmp/claude is not writable
- [BUG] Dog Da__ed claude code has deleted vital files 3 times this week.
- [BUG] Path-based permission rules fail due to undocumented bypass mechanism
- [BUG] Sandbox doesn't work with wildcard(asterisk)
- [Bug] Claude ignores explicit instructions about dangerous git operations
- [Feature Request] Restrict write access to .git directories even when parent directory is writable
- [Feature Request] Workspace-Level Privacy Settings for Training Consent
- [Feature Request] Implement Fine-Grained Tool Permissions for Agent Constraints
- [BUG] The current trust dialog lacks a convenient "Yes and don't ask again" option, forcing users to manually edit JSON files for each new project they want to trust permanently.
- [BUG] Claude Code repeatedly deletes/replaces Docker containers without checking for user data
- [BUG] Claude Code killing other Claude Code sessions without authorization
- [BUG] Permissions Bypass
- [Bug] False positive security risk flagging for non-cybersecurity code
- [Bug][cyber] Safeguard blocked session on repeated placeholder/test input with no cybersecurity content (req_011CcmaenvkPKwFzzPxH988v)
- [Bug][cyber] Safety block halted mid-session Android/ADB kprobe validation on user's own rooted test device (req_011CcmMR7BwnuqKiVs2tCaVR)
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011CccWXsf4mLsLPTXgq2X7T
- [Bug][cyber] Safety filter blocked drone protocol study for a personal FOSS ground station (req_011CccTJXknEJAy8jdAvRWLY)
- [Bug][cyber] Safeguard blocked drone protocol reverse-engineering for FOSS ground control (req_011CccTGmJJsqjDGWVZEokuA)
- [Bug][cyber] Safeguard wrongly blocked writing a defensive network port-scanning script (req_011CccTKSp9F8TgQL1fx7Xhe)
- [Bug][cyber] Safety filter blocked a legitimate request to audit and harden own website security (req_011CccNmQvSEeR2z4FsxBTyp)
- [Bug][cyber] Safety filter blocked capturing undocumented flight-control opcodes over device link (req_011CccKQww4Ww9U6zj1HkA22)
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011CccDxAt6Genk9nbgZU6Hw
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011CccCZpdhcjoebozMdRNoV
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011CccCXkDVJ6raHLj6LdPkB
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011CccCW7y8nBTXJ8R3Y3csk
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011CccCVVWuCx6QAQdrBqbo7
- [Bug][cyber] ClAudit false-positive in scan — req_011Ccc8x6HC6mg5pbxCtxqCJ
- [Bug][cyber] ClAudit false-positive in GlassFalcon — req_011Ccc6cF3zru4ATggqNoaox
- [Bug][cyber] ClAudit false-positive in android — req_011CcYJd2P9uUiFo9rWWG8VM
- [Bug][cyber] Safety filter blocks legitimate cybersecurity topic assistance in Claude Code session (req_011CcY1kqamR8G6sW1fDj6zF)
- [Bug][cyber] Wrongly blocked moving stdlib core modules into a FOSS Python SDK package and wiring container im (req_011CcXx4QDZwTyZLrwPi4jSz)
- [Bug][cyber] Safety block on AES/RC4 key analysis for unpacking a protected Android DEX binary (req_011CcWUjkz41RRupNdBuycUZ)
- [Bug][cyber] Blocks rolling back consumer drone firmware to a release predating an added restriction (req_011CcVtCm2xFhDbukwuYU5eB)
- [Bug][cyber] Persistent ADB-over-WiFi setup on rooted Android device blocked as unsafe (req_011CcWCiR9Jep5V6e2n6cebH)
- [Bug][cyber] Safety block stopped legitimate firmware rollback to remove unauditable closed-source SDK blob fr (req_011CcVsygksShGaBq1Rq1oZ6)
- [Bug][cyber] Firmware download/analysis for personally-owned drone blocked when extracting/disabling remote-ID (req_011CcU9WLfjszg2K9xq1ZKSS)
- [Bug][cyber] Safety block stopped firmware rollback to remove closed-source binary blob from owned hardware fo (req_011CcVsrEFUerapcnCR7xDAy)
- [Bug][cyber] Safety block stops legitimate drone firmware extraction and ADB analysis workflow (req_011CcUDY4dMjWrzVBGYbJHco)
- [Bug][cyber] Safety block stops legitimate drone firmware research and USB/ADB tooling work (req_011CcUCmrmzeYYStrRvqnVJJ)
- [Bug][cyber] False positive block on authorized reverse-engineering of closed-source drone SDK for interop (req_011CcVsnffpvCMeQZ4FixgRm)
- [Bug][cyber] Safety block wrongly stops static RE of white-box AES in proprietary firmware (req_011CcV4rLwqSCNGtqDMQF7Jd)
- [Bug][cyber] ClAudit false-positive in DJI — req_011CcV5MAAVyWRSqA8yDWNbJ
- [Bug][cyber] Downloading official factory firmware images for a consumer drone for offline analysis wrongly bl (req_011CcUERtdnX4RA8jqdyivCU)
- [Bug][cyber] Safety block prevented organizing local drone firmware files and research corpus into a FOSS repo (req_011CcUDXKhBvDGKQbPd3pT7n)
- [Bug][cyber] Safety block prevented decrypting drone firmware modules with bundled vendor keys for research (req_011CcUECPy19bngpixSPw7t9)
- [Bug][cyber] Safety block interrupts in-progress binary upload and remote service deployment coordination (req_011CcUWrQTSpRTHqgQH2Bjum)
- [Bug][cyber] Safety block stops crypto-secrets extraction workflow in embedded firmware research (req_011CcUBGf1tgrAnfN4wMxTrX)
- [Bug][cyber] Drone firmware version diffing blocked during reverse-engineering tooling setup (req_011CcUAc6sZFmQFqpuRBLsct)
- [Bug][cyber] Safety block wrongly halted adding a local video viewer that re-streams a drone camera feed for i (req_011CcURZaYN2moXG9LBeFaJd)
- [Bug][cyber] Safety filter blocked building an in-app video viewer that proxies/relays an RTSP stream (req_011CcUR4SjW19NDrt4CKJMUX)
- [Bug][cyber] Safety filter blocks legitimate cybersecurity topic mid-session, forcing session restart with no (req_011CcUFqnKpBbFKH9eyjegU1)
- [Bug][cyber] Safety block fires during USB device firmware defensive-hardening with OSS tools (req_011CcUFpr7jdLiNHaV11xjm4)
- [Bug][cyber] Cybersecurity safety classifier blocked legitimate USB device detection work on a connected hobby (req_011CcUFmindDBqnQRLsa8yXC)
- [Bug][cyber] SSH key enumeration and device detection via shell script blocked during authorized hardware inte (req_011CcUFgWqu1qfBMkxFZ7gCu)
- [Bug][cyber] False positive block on cloud IAM role enumeration and least-privilege policy review (req_011CcUFeRHE9JvWSttJS2mGt)
- [Bug][cyber] Safety block stops official firmware download for drone defensive hardening (req_011CcUEuZuSaJBwtqHUVRA1K)
- [Bug][cyber] Safety block incorrectly halts firmware extraction and encryption-key analysis for defensive rese (req_011CcUEHYKSUpWP2jeLRZWc8)
- [Bug][cyber] ClAudit false-positive in DJI — req_011CcUECPy19bngpixSPw7t9
- [Bug][cyber] ClAudit false-positive in DJI — req_011CcUDY4dMjWrzVBGYbJHco
- [Bug][harness] Safety block halts user-approved SSH service-status check via fleet skill, blocking authorized
- [Bug][cyber] False positive blocks running and monitoring an authorized signaling-deployment automation script (req_011CcQaHugdTRWt8fvmgtUDf)
- [Bug][aup] Cyber safeguard false-positive blocks automated prediction-market order placement script
- [Bug][harness] Secrets block stops writing local automation credentials to a user-owned config file
- [Bug][harness] Safety block halts WLAN PUT update enabling WPA3 SAE with PMF required during transition setup
- [Bug][harness] Safety block fired on user-directed skill execution accessing shared container state via remote
- [Bug][harness] Safety block stopped restoring a dropped reverse-proxy backend listener from a verified prior c
- [Bug][harness] Safety block halts authorized SSH key bootstrap (password login to install pubkey) on user-owne
- [Bug][harness] Safety block stopped fixing a misconfigured DNS/tunnel access entry, conflating it with credent
- [Bug][harness] Safety classifier blocked user-authorized creation of a fully-scoped API token for infra fixes
- [Bug][harness] Safety classifier blocks saving a newly-minted, user-authorized API token to its credentials fi
- [Bug][harness] Safety block prevents automated installer script from applying downloaded package updates on a
- [Bug][harness] Live USDC send blocked mid-port despite user explicitly ordering full feature port to completio
- [Bug][harness] Safety block wrongly halts user-authorized irreversible financial transaction despite explicit
- [Bug][aup] Deleting Claude memory/history files from a local project directory blocked by cyber safeguards (req_011Cbu1oUB6bS3HknzaE7C5a)
- [Bug][harness] Safety block incorrectly halts root-authorized systemd unit cleanup on production host during i
- [Bug][harness] Credential lookup in user-specified config path blocked as unauthorized exploration
- [Bug][harness] Legitimate agent scope expansion to find valid credentials blocks reading config files the user
- [Bug][harness] Listing CF Access policies blocked as recon when debugging auth bypass on user's own domain
- [Bug][harness] Safety block prevents shell read-and-inject of an existing secret into a config file
- [Bug][cyber] Safety block stops account compromise forensic audit for user remediation report (req_011CcQG5ySBGsd643wCB734S)
- [Bug][harness] Adding inter-VLAN firewall allow rule via controller API blocked as credential exploration