Security issues on Linux — page 3
Issues the maintainers labelled both platform:linux and area:security.
773 issues · 266 open · 507 resolved (66%) · first seen May 20, 2025
Is this getting better or worse?
This class of problem is still growing. 601 new reports in the last 90 days vs 46 in the 90 before — +1207%. The open backlog peaked at 381 in 2026-07 and sits at 266 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
162 of these reports name the Claude Code build they were running, spanning 90 releases. Heaviest reporters:
- Claude Code v2.0.76
- Claude Code v2.1.207
- Claude Code v2.1.206
- Claude Code v2.1.201
- Claude Code v2.1.247
- Claude Code v2.1.241
- Claude Code v2.1.234
- Claude Code v2.1.198
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 46 days across 507 closures. Of the 507 closures with a recorded reason, 10% were closed as completed and 455 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
52 of these issues post a workaround someone says worked. The highest-engagement ones:
- bypassPermissions mode not working in VS Code extension
- issue was reproduced on after upgrade IDE-VSCODE-CC-01-v1: Workaround — bypassPermissions in VSCode Extension Linked rule: [IDE-VSCODE-CC-01-v1](IDE-VSCODE-CC-01-v1.md) Upstream: [anthropics/claude-code 20536]( --- Envir…
Found in the thread of #20536 · still open - [BUG] Linux sandbox broken - bad bwrap calls and no allow permissions
- …ect root instead of protecting .git/HEAD, .git/config, etc. Workaround Added rooted patterns to .gitignore: /HEAD /config /hooks /objects /refs /.bash profile /.bashrc /.profile /.zprofile /.zshrc /.gitconfig /.gitmodule…
Found in the thread of #17727 · still open - [BUG] .claudeignore not ignoring private files
- …oses such as software testing or inter agent documentation. Workarounds to this scenario include changing while the agents are working and restoring it when doing git operations, or allowing agents to ignore which leads…
Found in the thread of #16704 · resolved - [BUG] ask list is ignored when "Bash" is in allow list
- …ands) and safety (protection against destructive commands). Workarounds attempted (none work) : - - Bypasses everything including ask list - - Prompts for every new command type
Found in the description of #6527 · still open - [FEATURE] GPU device passthrough in sandbox mode
- I did end up with a workaround, but this would be a really good feature to support natively so trickery is not required. 1. Ensure ~/.local/bin/ is on your PATH before /usr/bin 2. Make ~/.local/bin/bwrap: 3. Relaunch cla…
Found in the thread of #13108 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 201–300
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 773 matches; the statistics above cover all 773.
- [Bug][harness] Safety block stopped applying explicitly-requested iptables port-restriction rules during defen
- [Bug][harness] Safety block prevents reading container AD config to survey directory infra for authorized sand
- [Bug][harness] Read-only audit incorrectly blocked while only inspecting a service config, not modifying it
- [Bug][cyber] Safety block prevents generating PDF report of cloud IAM OAuth consent audit findings (req_011CcQE9KUHg8rXt4ZXeeAYJ)
- [Bug][cyber] Cloud IAM tenant security audit of admin roles, app credentials, and OAuth consent grants wrongly (req_011CcQDjM6MNUBXuuk5VetJo)
- [Bug][aup] Cloud-IAM incident-response sweep checking web servers and container infra for compromise blocked (req_011CbwvtUn8Nam1CTDRokVFa)
- [Bug][harness] Safety block halted authorized build/deploy of no-delegate binary to onboarding-blocked host
- [Bug][harness] Safety block wrongly halts authorized restart of live production service after explicit "go" ap
- [Bug][aup] Cyber safeguard blocked editing a contact-form tool's README explaining its privacy-by-design data (req_011CbxA24W7iVNoqJBGVR4eb)
- [Bug][harness] Safety block prevents SSH to backend host and authorized API-token curl during requested deploy
- [Bug][harness] Safety block halts authorized one-pass deploy by refusing to fetch the tunnel binary needed to
- [Bug][harness] Safety block halts service config fix by flagging agent-chosen wallet address written to remote
- [Bug][harness] Safety block halted authorized DB snapshot prep during scoped infra-wipe task, conflating it wi
- [Bug][harness] Safety block halted applying VPN/CF-tunnel API-key IP allowlist restriction on audited project
- [Bug][harness] Safety block halted VM disk migration to a host after misflagging an in-use storage dataset as
- [Bug][harness] Safety block halts authorized read of API key names/tails to locate an explorer/indexer key for
- [Bug][harness] Real-money send blocked despite security-required explicit-destination confirmation already giv
- [Bug][harness] Safety block halted authorized recovery of two on-chain bets missing from betting-history table
- [Bug][harness] Safety block halted authorized WMS admin password reset via database, misreading it as disablin
- [Bug][harness] Cert auto-renewal request wrongly blocked agent from installing standard ACME client on router
- [Bug][harness] Safety block halted bulk cleanup of stale directory objects during an authorized batch task
- [Bug][cyber] Safety filter blocks setting up a RustDesk remote-desktop session to an owned workstation (req_011CcCHsyr5uPwkMkuQBScVK)
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcCJ6gHGSKLjUEdaEbfty
- [Bug][cyber] Safety filter blocked drafting a GitHub issue title reporting an over-broad cybersecurity block (req_011CcCJA4N936FzQRbcCH6pz)
- [Bug][cyber] Safety block prevented reading and explaining an open-source remote-desktop tool's source code (req_011CcCJxQC2pmzMCHKWSoqGS)
- [Bug][harness] Safety block halts legitimate retrieval of a stored remote-access password for an authorized su
- [Bug][harness] Safety block halts authorized printer-driver/feature-enable troubleshooting on a production RDS
- [Bug][cyber] ADB app sideload and GPS location simulation setup for a mobile game wrongly blocked (req_011CcFDUVe6dCBb2dVSWsjPf)
- [Bug][harness] Safety block halted authorized re-provisioning of a leak-free, API-restricted cloud LLM key aft
- [Bug][harness] Off-hours binary force-redeploy and service install on three self-selected production hosts blo
- [Bug][cyber] Safety block halted legit incident-response RDP/VPN log forensics tracing an unauthorized intrusi (req_011CcG51GkXNkgk7ChGuQwPB)
- [Bug][cyber] Blocks adding event-log forwarding to a syslog server via the authenticated agent API (req_011CcG6JTT3iUfvhYd6KK4sr)
- [Bug][cyber] IAM exemption flow blocks reviewing M365 directory-permission grant 403 and AppLocker audit logs (req_011CcGGZbz5xF7AG6jSRhK39)
- [Bug][cyber] Cloud IAM admin work in own tenant blocked: reading service-account creds and querying directory (req_011CcGkCfkESvJWvNcgayNhD)
- [Bug][cyber] Safety classifier wrongly blocks routine sysadmin work integrating CDN and reverse-proxy logs int (req_011CcGkEPtYTU36Z5XueW83z)
- [Bug][cyber] Defensive SIEM rule-override tuning and benign agent binary RE wrongly blocked as cyber (req_011CcGsa9Rmd555hKJSXBc5x)
- [Bug][cyber] Safety block stopped reverse-engineering a vendor connector binary to verify it isn't exfiltratin (req_011CcGsYf2CNedQvoSE5twQi)
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcGsmyfyZDbeYraBgMynW
- [Bug][aup] Tuning Wazuh authentication_success rule overrides and analyzing endpoint connector behavior wrongl (req_011CcGtRDcQEWCgaMB7KHMbE)
- [Bug][cyber] Safety block stopped configuring SIEM logging of an integration agent's plaintext order/customer (req_011CcGtncA4PSzrxrAq3CsnP)
- [Bug][cyber] Safety block stopped tuning SIEM detection rules to reclassify benign accounting-connector API tr (req_011CcGui76KzkTPWm5QmdZ1d)
- [Bug][cyber] Safety block stopped generating a vendor-integration audit report section summarizing parsed orde (req_011CcGvJbDTbhNumnpWK9Khy)
- [Bug][cyber] Safety block prevented OSINT/Shodan exposure check of own infra during internal vendor connector (req_011CcGvGgE2gecADLunFUMgV)
- [Bug][cyber] Safety block halts completion of internal blue-team defensive incident report on auth attack vs V (req_011CcGvh9W2efdV3fZXtP5SW)
- [Bug][cyber] Safety block prevented documenting existing internal AD/identity defensive-hardening module integ (req_011CcGwMehFzzAyEMKRLDq51)
- [Bug][cyber] Safety block prevents analyzing AD attack telemetry (top MITRE techniques per account) for IR tri (req_011CcGwTMpAkFjBUeMpxhLwH)
- [Bug][cyber] Safety block halts defensive triage of aggregated MITRE ATT&CK technique counts from auth logs (req_011CcGwVhvhSJx9reWFcUij2)
- [Bug][cyber] Defensive hardening to ingest order logs into tamper-evident store and AppLocker-allow a vendor b (req_011CcGwWubT644CBD2v47NEz)
- [Bug][cyber] Safety block prevents Shodan API lookup of owner's own domains for defensive exposure review (req_011CcH164PJg5iAAB8A8nv4W)
- [Bug][aup] GPS location-spoofing test app flow misclassified, blocking systemizing a local APK via Magisk modu (req_011CcH3LBfUpgMszQmg3PexU)
- [Bug][harness] Safety block stopped adding skip-verify TLS dialer so relay client trusts CDN origin cert behin
- [Bug][cyber] DNS sinkhole/wildcard resolver config wrongly blocked while restricting LAN to a single upstream (req_011CcJonk8TZPZEWqHWcckDs)
- [Bug][cyber] DNS resolver config change blocked: setting LAN DNS to wildcard-respond locally while restricting (req_011CcJpUgS5AA3rKvYfd9kNV)
- [Bug][harness] Safety block wrongly halted authorized SSH into own gateway to add DNAT port-53 redirect rule
- [Bug][cyber] Safety block halted writing mobile-responsive RustDesk auto-detect/install prompt for fleet admin (req_011CcKCg7aHRtHmTkCiunNGE)
- [Bug][cyber] Cloud IAM remediation blocked: granting Graph API permission to apply OAuth consent hardening fix (req_011CcPmN9yVzS7grFsWeb6N1)
- [Bug][harness] Safety block prevents creating Access bypass rule needed to test break-glass recovery flow end-
- [Bug][cyber] Safety filter wrongly halts legitimate cloud IAM audit of admin roles and OAuth grants (req_011CcPkE7Ne9nyS4y8TMkfzV)
- [Bug][harness] Safety block stops authorized remote provisioning command on own infra to re-enroll a host agen
- [Bug][harness] Cache-purge step blocked from reading project credential file to authenticate edge cache invali
- [Bug][harness] Safety block halted deploying an already-CF-managed site to its provisioned container via root
- [Bug][harness] Safety block halted local build of read-only Defender admin dashboard before UI render verifica
- [Bug][harness] Safety block halts authorized publish of signed agent build to release dir during in-scope sess
- [Bug][harness] Safety block wrongly halted adding two authorized internal staff to a geo-gated browser-RDP all
- [Bug][cyber] Auditing own M365 tenant for missing anti-spoof mail-flow rule after registrar defederation false (req_011CcPEezHx9SZ9QBaEPGSMg)
- [Bug][cyber] Safety block halted forensic triage of an internal BEC vendor-impersonation invoice-fraud email (req_011CcPHGQUTEyyNZENQ41hkH)
- [Bug][cyber] Authorized BEC incident investigation of compromised email account blocked mid-forensic-report (req_011CcPHrNhFQUoaLV3BSt44u)
- [Bug][cyber] Safety block halted legitimate BEC incident-response: securing a compromised email account and bu (req_011CcPJ5PjNCtFZDjMvawBFB)
- [Bug][cyber] Safety filter blocked triaging a suspected compromise on my own machine mid-investigation (req_011CcPJArTbepdvraQ4bBuAr)
- [Bug][cyber] Safety block stopped read-only IR mailbox triage and credential lockdown via Graph API in authori (req_011CcPK7qhVF6zoCygQv6LWY)
- [Bug][cyber] Claude Code safety false-positive on legitimate work (req_011CcPKjB1Zm8zZe541NDjZW)
- [Bug][cyber] PII-scrubbing CLI for cloud IAM tenant/directory output blocked while filing a GitHub issue (req_011CcPL22bXVcMfDDfnLRmys)
- [Bug][cyber] Safety filter blocked a session on random keystroke input containing no cybersecurity work (req_011CcPL95S8HbEbzqnL6PBK3)
- [Bug][cyber] ClAudit false-positive — req_011CcPQ3KbDroW7QoqCcy8Q7
- [Bug][cyber] ClAudit false-positive — req_011CcPcSDfZpmh6T4DZ3A9b5
- [Bug][cyber] ClAudit false-positive — req_011CcPS6LFjCBShF3Xnr6cH9
- [cyber] False-positive block (req_011CcPQ3KbDroW7QoqCcy8Q7)
- [BUG] "Human:" messages cause Permission Mode: Auto to allow unauthorized tasks
- [BUG] autoUpdates: false in ~/.claude.json is not respected on native installation — CLI self-updates on launch
- [BUG] Claude Code escapes systemd transient scope at startup, defeating user-imposed memory caps
- [BUG] CLI binary spawns subprocesses (e.g. gh) outside the permission model — invisible to allowlist audits
- [Bug] Malware check prompts causing rapid quota exhaustion and code analysis refusals
- bypassPermissions on agents ignores settings.local.json allowlist
- managed-settings.json: deny Read(**) does not block reads outside allowed paths
- [BUG] Sandbox directory /tmp/claude causes permission conflicts for multi-user systems
- [BUG] rm command bypasses permission system on Linux (works correctly on Windows)
- Feature Request: Native GUI Password Prompt for Sudo Commands
- Allow list exact match should take precedence over deny list wildcard pattern
- [BUG]
- [BUG] `mcp add` replaces env var names with actual env var value
- [BUG] Unauthorized Command Execution via Ambiguous Instruction
- [Bug] Unauthorized Directory Traversal Attempts During Initialization
- [BUG] Dangerous system-breaking sudo chown suggestion in `claude doctor` for Ubuntu users
- [BUG] Claude Code is unable to respond to this request, which appears to violate our Usage Policy
- [Bug] Anthropic API Error: Overly aggressive [bio] classifier hard-refusing legitimate penetration-testing instructions
- [BUG] Bug report: assistant fabricated a user turn and system prompts inside its own response, then executed them
- [Bug] Anthropic API Error: Incorrect Cyber Safeguard Trigger on Benign Request
- [Bug][cyber] Security audit of owned app auth logic incorrectly blocked (req_011Ccpp5ieFdZ9haxvXbxoT3)
- [Bug][cyber] Safety block halted DUML protocol reverse-engineering for a drone ADS-B decoder (req_011CcmHFiAtBT2k4h4isR8iy)
- [Bug] Safety classifier false-positives on defensive security patching, causing silent mid-session model downgrade