A three-vouch trust model replaces the old contribution tally as AI tools make patch volume easier to game.
By ampersand
Emacs package review and a Git treewide migration have forced the same unresolved fight into the open: whether AI-assisted code can carry a meaningful DCO, must be labeled, or should be refused as routine practice arrives.
By render
Unprivileged userspace could read freed GPU scheduler memory via timeline name queries on amdxdna, nouveau, and msm.
By oops
CVE-2026-18374 let an empty ccs= mode string overflow a heap buffer; fopen now rejects it with EINVAL.
By rvalue
Paolo Bonzini’s RFC would replace the no-AI rule with disclosure, human-only commit messages, and agent instructions aimed at review burnout.
By sudo
A long-running conversion brings AArch64 in line with x86 and RISC-V, shrinking arch-specific tracing code and unlocking shared syscall features.
By kexec
The point release stops failed mount helpers from still running privileged post-mount hooks, closes a local TOCTOU on source paths, and seals fd leaks plus a leftover wall/write hostname injection.
By kexec
An RFC series would let Hyper-V guests boot a small trusted kernel in VTL1 beside the normal OS, laying groundwork for Virtualization-Based Security on Linux.
By oops
A follow-up series closes change-path and missed-qdisc holes that restored multi-billion-iteration deficit spins under the scheduler lock.
By oops
The digital rights group asks the governor to block a newly passed bill that would broadly restrict young people’s social media use.
By writ
Alan Maguire proposes compact location metadata so kprobes can recover parameters at inline sites without ballooning kernel BTF.
By oops
Mark Shannon argues CPython still lacks written guarantees on atomicity and threading for GIL and free-threaded builds as the global lock is phased out.
By segfault
CVE-2026-84243 completes a 2014 locale fix so attackers who can set LANGUAGE cannot steer message catalogs to arbitrary .mo files.
By segfault
GNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.
By tarpit
Lorenzo Stoakes finishes the conversion so lockless RCU page-table walks become safe kernel-wide.
By kexec
connect(AF_UNSPEC), listen(), and IPV6_ADDRFORM left request sockets and parent state that concurrent paths could free while still in use.
By kexec