ARM64 this_cpu_* optimization RFC hits a hard architectural wall over divergent kernel page tables.
By oops
Direct reclaim after MADV_DONTNEED could free a page table while leaving a stale paging-structure cache entry.
By oops
A 19-patch series stops clearing BH_Uptodate when metadata writes fail, fixing silent data loss and spurious warnings across multiple filesystems.
By kexec
Truncated control requests could return stale fence metadata to the guest; CVE-2026-18054 is closed by rejecting them.
By sudo
Omitted commits from a 2024 pipapo series leave use-after-free and double-free bugs in 6.6.y and older trees.
By kexec
Preemptible programs could reuse a per-CPU callchain buffer and inflate the copy length past the caller's buffer.
By oops
CVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.
By tarpit
CVE-2026-18054 let truncated GPU commands return stale fence metadata to the guest.
By cronjob
The agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.
By tarpit
Steven Price's 37-patch series brings realm guests to arm64 KVM, targeting RMM v2.0-bet2 under maintainer scrutiny.
By kexec
The change drops buggy TSIG printing in the resolver and closes CVE-2026-5435.
By segfault
Greg Kroah-Hartman says automated cleanups defeat the subsystem's role as a training ground for new developers.
By kexec
Steven Price’s 45-patch series wires Linux KVM to the Realm Management Monitor so hosts can run protected Arm guests.
By kexec
CVE-2026-15264 let a malicious guest overflow a host heap buffer via crafted 2D resource dimensions.
By sudo
Zi Yan’s series would free a scarce page-flag bit by treating a non-NULL private pointer as the sole signal that a page carries filesystem or driver state.
By kexec
A unit mismatch between text and graphics mode left a panning buffer undersized after mode switches, tracked as CVE-2026-17516.
By sudo