Flatpak stack CVEs reopen the desktop sandbox trust question
A burst of bubblewrap, xdg-dbus-proxy, and Flatpak fixes shows how setup-time symlink tricks and D-Bus filter gaps still undermine the isolation users treat as a boundary.
By tarpitA burst of bubblewrap, xdg-dbus-proxy, and Flatpak fixes shows how setup-time symlink tricks and D-Bus filter gaps still undermine the isolation users treat as a boundary.
By tarpitNGCC's first round of post-quantum submissions is collapsing under human and machine cryptanalysis, and the fastest breaks came from an AI running on its own.
By staffFrom a Claude-found lattice break to AI-draft floods at the IETF and a bot-mediated fight on emacs-devel, free software and standards communities are arguing what counts as legitimate help, what is noise, and what threatens how work is governed.
By tarpitJim Cromie's three-patch series cuts bulk symbol attach from hundreds of milliseconds to tens, after production stalls in fleet observability tools.
By oopsCVE-2024-47702 is closed by rejecting verifier paths that can corrupt skb data pointers and crash the kernel.
By oopsA flawed retransmission path can send leftover buffer bytes to a peer or abort the process when a handshake write is suspended mid-message.
By tarpitCVE-2026-97395 affects Polaris before 1.8.0 when writers can set Iceberg FileIO endpoints that the server honors with operation credentials.
By tarpitA 22-patch bpf-next series adds bpf_unwind(), verifier and x86 JIT support so frames can release locks and references instead of being discarded.
By oopsA nested push from kretprobe NMI context could publish past an unfinished entry, letting another CPU pop a NULL or stale pointer.
By oopsThe agency will specify a single KAT-matchable signing procedure and keep more aggressive Falcon optimizations for later special publications.
By tarpitMaxime Ripard’s generic DRM bridge would load panel init sequences from userspace, echoing HID-BPF, but reviewers flag early-boot and upstream risks.
By kexecA second KVM module would share arm64 code and drive the Start Arm Execution instruction so s390 hosts can accelerate ARM virtual machines.
By kexecMisordered TLB fix in Linux 6.1, 6.6, and 6.12 left processes able to run with stale translations.
By oopsCVE-2026-19444 is a medium-severity flaw in several kubectl release lines that only affects clients running on Windows.
By sudoAn unvalidated Extended Transport Protocol offset on virtual CAN triggers a NULL dereference and kernel panic without hardware or races.
By kexecA steal governor lets paravirtualized guests shrink their usable CPU set under host contention, cutting preemption costs beyond lost cycles.
By kexecAlistair Francis posts a standalone Rust SPDM stack and PCIe CMA TSM path so the kernel can verify devices before trusting them.
By oops