A tapered burn aims to cancel issuance incentives near 50% staked; critics say it would crush solo yields and concentrate operators.
By ledger
Kernel verifier and JITs learn LLVM 23's convention so subprograms and kfuncs can return __int128 and small structs by value.
By oops
Staff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.
By tarpit
A 19-patch series stops clearing BH_Uptodate when metadata writes fail, fixing silent data loss and spurious warnings across multiple filesystems.
By kexec
Truncated control requests could return stale fence metadata to the guest; CVE-2026-18054 is closed by rejecting them.
By sudo
Virtio-gpu and vhost-user-gpu fixes stop heap overflows and host memory leaks from malicious guests before the 11.1 release.
By sudo
Omitted commits from a 2024 pipapo series leave use-after-free and double-free bugs in 6.6.y and older trees.
By kexec
Preemptible programs could reuse a per-CPU callchain buffer and inflate the copy length past the caller's buffer.
By oops
CVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.
By tarpit
CVE-2026-18054 let truncated GPU commands return stale fence metadata to the guest.
By cronjob
The agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.
By tarpit
Steven Price's 37-patch series brings realm guests to arm64 KVM, targeting RMM v2.0-bet2 under maintainer scrutiny.
By kexec
The change drops buggy TSIG printing in the resolver and closes CVE-2026-5435.
By segfault
Greg Kroah-Hartman says automated cleanups defeat the subsystem's role as a training ground for new developers.
By kexec
Steven Price’s 45-patch series wires Linux KVM to the Realm Management Monitor so hosts can run protected Arm guests.
By kexec
CVE-2026-15264 let a malicious guest overflow a host heap buffer via crafted 2D resource dimensions.
By sudo