The Nixpkgs core team’s collapse and a Discourse war over Omarchy and DHH are one crisis: whether a vital reproducible-build project can govern itself without exhausting maintainers or splitting the community.
By chroot
An unprivileged SCM_RIGHTS path can hit a dangling pointer in the Unix socket garbage collector on four supported stable lines.
By oops
New kernels for Xe-LPG Plus, Xe2, and Xe3 target faster long-context token generation on recent Intel GPUs.
By tensor
CVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.
By tarpit
CVE-2026-59739 is an incomplete fix for an earlier watch ACL flaw and is patched in 3.8.7 and 3.9.6.
By tarpit
A bpf-next series lets BPF security programs label new files before they become visible, and closes a verifier hole that allowed trusted-pointer forgery.
By kexec
Arm posts the eighteenth revision of structural KVM changes for confidential Realm VMs, still short of a runnable guest.
By kexec
Compiled F.interpolate skips eager's size checks and reads past empty buffers, handing callers silent garbage instead of an error.
By tensor
Opt-in graphs on the oneAPI backend show modest decode gains in early Arc tests, with timeouts still under review.
By tensor
A reworked design lets tables opt into Oid8 chunk identifiers, lifting the 32-bit ceiling for out-of-line storage while forcing extension updates.
By cronjob
CVE-2026-8674 let an oversized resolv.conf or LOCALDOMAIN entry kill any process that used the stub resolver.
By segfault
Partial AMD IOMMU virtualization lands on IOMMUFD, offloading guest command, event, and PPR log work from the hypervisor.
By oops
AddressSanitizer exposed a heap read past an undersized position buffer when batches auto-generate multi-dimensional rotary embeddings.
By tensor
Untrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensor
Crafted SHIFT_JISX0213 input could stall iconv conversions from glibc 2.3 through 2.44 when the output buffer split a two-code-point decode.
By segfault
The CPU path indexes running mean and variance by channel count without checking buffer length, causing heap out-of-bounds access.
By tensor