kexec
Kernel & Low-Level desk
Kernel gains in-tree agent skill for correct Fixes tags
Sasha Levin proposes a portable find-fixes procedure after maintainers flagged widespread wrong attribution in stable backports.
Ext4 buffered I/O moves to iomap in large opt-in series
Zhang Yi’s 31-patch v7 lands the core conversion and a new disksize-pending scheme, still off by default until more features catch up.
Kernel fix blocks UAF in lazyfree huge-page reclaim race
An unprivileged race of MREMAP_DONTUNMAP against transparent huge page discard could free anon_vma structures still referenced by a restored mapping.
Linux netdev adds fwnode PCS provider API for external serdes
Christian Marangi’s series gives phylink a producer-consumer model for Physical Coding Sublayer devices and lands first support on Airoha AN7581.
Linux watch queue race lets unprivileged users panic the kernel
A fix makes sizing of key-notification pipes atomic so concurrent posters cannot hit a null buffer and crash the system.
SPARC64 gains Linux seccomp filter support
The architecture was one of the last without the BPF sandboxing Docker, systemd, and Flatpak rely on.
Kernel pin-init adds safe sibling-field self-references
Gary Guo’s series lets pinned Rust structs borrow between fields without allocation, landing advanced variance tools under a tight-use agreement.
get_maintainer change would stop auto-CCing every patch to LKML
A proposed fix treats THE REST as a true fallback so subsystem lists no longer share the firehose with linux-kernel by default.
Who owns the patch when the model wrote it?
Kernel maintainers and Emacs developers are drawing the same line at once: undisclosed LLM help is not a process detail, it is a trust and philosophy problem.
Linux skbuff core turns crash BUG_ONs into recoverable warnings
Josef Bacik's net-next work replaces 17 hard panics in packet buffer code with WARN_ON_ONCE and existing error returns, after dozens of real-world crashes including some reachable from user namespaces.
LINBIT submits DRBD 9 multi-peer rework to mainline kernel
A 20-patch series aims to close a decade-plus gap between the out-of-tree module and the single-peer code still shipped in-tree.
KVM arm64 gets basic plumbing for Arm CCA Realms
A trimmed v22 series adds VM-type abstractions and non-runnable Realm scaffolding so confidential guests can share common paths with pKVM.
Linux SCSI target fixes eight SG overruns hit via vhost-scsi
Guest commands through page-per-entry virtqueue layouts could push host target code past scatterlist bounds into adjacent memory.
Linux net-next gains core in-kernel QUIC transport stack
Xin Long’s v16 series adds sockets, streams, paths, crypto, and congestion control so kernel services and user space can speak QUIC without a userspace transport.
bnxt_en DMA faults after link-layer headroom change
A latent short-packet padding bug in Broadcom’s NetXtreme-E driver, exposed by a kernel headroom bump, was taking interfaces down within minutes.
BPF unwind pads race to free Rust panics from the verifier's grip
Multi-revision series for exception cleanup landing pads aim to let Rust Drop run on panic, while maintainers push back on verifier complexity and edge cases with tracing.
BPF verifier gains scalar evolution to widen bounded loops
Eduard Zingerman's 43-patch series lets the kernel treat loop induction variables as ranges instead of enumerating every value.
Linux kernel adds Rust PCI SR-IOV driver support
A new abstraction layer lets Rust physical- and virtual-function drivers configure SR-IOV and share PF-owned data safely until VF teardown finishes.
MGLRU RFC adds frequency-guided promotion, claims double-digit gains
Kairui Song’s third RFC series promotes hot pages on access instead of at eviction, reporting 10–40% better results while freeing one page-flag bit.
Kernel keeps anonymous THPs intact across swap
A 30-patch series introduces PMD-level swap entries so huge anonymous mappings survive swap-out and restore in one fault instead of shattering into PTEs.
KVM hardens teardown against host memory corruption
Nested VMX could write guest state into the wrong process address space while a VM dies, and the fix also closes a PowerPC shadow-page leak.
NUMA balancing filters were stranding hot pages on CXL memory
Meta reports major latency and bandwidth gains after decoupling tier promotion from socket-placement heuristics in the kernel scheduler.
Hazard pointer series fixes race, draws Linus on ptr_eq
Mathieu Desnoyers posts hazptr updates with a try-acquire fast path; Torvalds rejects hiding pointer values to preserve address dependencies.
BPF-driven MIPI-DSI panels proposed to speed OEM display support
Maxime Ripard’s generic DRM bridge would load panel init sequences from userspace, echoing HID-BPF, but reviewers flag early-boot and upstream risks.
IBM posts KVM series for ARM64 guests on s390 mainframes
A second KVM module would share arm64 code and drive the Start Arm Execution instruction so s390 hosts can accelerate ARM virtual machines.
J1939 CAN bug lets local user panic Linux with bad packet offset
An unvalidated Extended Transport Protocol offset on virtual CAN triggers a NULL dereference and kernel panic without hardware or races.
Linux scheduler gains steal-time preferred CPUs for VM guests
A steal governor lets paravirtualized guests shrink their usable CPU set under host contention, cutting preemption costs beyond lost cycles.
BPF verifier series adds scalar evolution for bounded loops
Eduard Zingerman proposes algebraic loop analysis so induction variables can be treated as ranges instead of enumerated values.
Virtualized swap stalls on cgroup memory.swap semantics
Meta’s vswap work would free zswap from disk slots, but changing how memory.swap is charged risks breaking production limits at Google and elsewhere.
Linux mm series reworks folio refcounts for read scalability
Optimistic increments replace CAS loops under contended IO; Linus has acked the core change while free-path races stay open.
nf_tables UAF fix headed to Linux 6.12, 6.6, and 6.1 stables
A device-unregister path could free a binding chain while the netdev event walker still held a pointer to it.
Linus tightens rc rules after networking pull includes old ovpn fixes
Torvalds pulled Linux 7.3-rc5 net updates but said post-merge fixes must be regressions or critical, not long-standing bugs.
BTF gains compact encoding for inline function probe sites
Alan Maguire's bpf-next series lets tracers attach kprobe-style instrumentation at inlined call sites without ballooning type data.
BPF stack limit rises to 2 KiB on x86-64 and arm64
A verifier and JIT series lifts the long-standing 512-byte frame budget for JITed programs while leaving the interpreter and other architectures unchanged.
BPF stack limit proposed to rise from 512 bytes to 2 KiB
x86-64 and arm64 JITs would get the larger budget; the interpreter and other architectures stay at 512 bytes.
Kernel series fixes coredump UAF, truncated dumps, and hangs
Christian Brauner’s multi-patch stable-bound work closes races among coredumps, signals, freezers, and io_uring workers.
From blanket bans to AGENTS.md: open source tries to govern AI code
Kernel selftests, QEMU policy drafts, review-bot injection risks, and Free Software fights over LLM packages are forcing projects to replace unenforceable AI prohibitions with explicit rules while licensing and security stakes remain open.
When dual maintenance ends: Rust Binder deletion and the nova-core binding fight
A proposal to delete the C Binder driver and NVIDIA’s expanding Rust vGPU stack force the kernel community past experiments into the harder question of retiring C subsystems.
Linux NVMe adds TP8028 cross-controller path recovery
Host and target support for Rapid Path Failure Recovery lets multipath NVMe fence a dead path before failover, avoiding double completion and data corruption.
BPF exception unwind gains cleanup pads for Rust Drop
Yonghong Song's bpf-next series lets bpf_throw() run compiler-emitted landing pads so frames can release locks and owned objects on the way out.
Linux perf drops embedded Python for standalone scripts
Ian Rogers's 49-patch series finishes moving perf analysis scripts onto a C extension module, cutting overhead and build complexity.
BPF exception cleanup pads clear path for Rust panics
Kernel support for LLVM 23 unwind tables lets bpf_throw() run Drop glue before discarding frames that hold locks or referenced pointers.
Linus demands real users before hazard pointers land
McKenney and Desnoyers floated a full RFC series; Torvalds wants core conversions and real workload numbers, not torture tests.
NOMMU GUP pin path fixed after io_uring use-after-free
On kernels without an MMU, pin and unpin refcounts were asymmetric, so repeated io_uring fixed-buffer registration could free pages still mapped by userspace.
Stable kernels need alternate fix for AF_UNIX UAF
CVE-2026-64109 still affects long-term trees after mainline removed a dangerous tail length read unsuitable before 6.5.
Virtual swap layer proposed to decouple Linux PTEs from backing
Nhat Pham's v5 series lets zswap and zero pages claim swap entries without pre-allocating physical slots, and retunes memcg swap charging to match.
perf trace stops vetoing syscalls for every concurrent tracer
Ian Rogers moves filtering into BPF maps so a single session can no longer drop raw_syscalls events system-wide, and the exclusive test tags that hid the problem can go.
Linux NUMA series unblocks promotion of hot slow-tier memory
Filters meant to calm socket placement were stranding hot pages on CXL, and Meta patches separate the two jobs.
BPF gains common cgroup attach path for struct_ops maps
A bpf-next series reuses the existing bpf_link cgroup model so groups of BPF programs can share attach, ordering, and query semantics, with TCP sock ops as the first consumer.
Google floats stealable PING futexes for Linux
RFC would trade strict PI handoff for lock stealing and proxy execution; maintainers call it premature and flag lockup risks.
Linux VFIO series adds CXL Type-2 accelerator passthrough
NVIDIA’s Manish Honap posts work that lets guests drive a virtual HDM decoder and device reset while the host keeps the physical mapping.
NVIDIA vGPU VFIO driver sparks Rust rewrite debate
A C-based variant driver for nova-core draws a full Rust counter-proposal and VFIO maintainer pushback on long-term review capacity.
Linux makes per-VMA locks unconditional across all configs
A series from Dave Hansen and Suren Baghdasaryan drops architecture gates so binder, TCP, and generic code can lock individual VMAs without mmap_lock fallbacks.
ASUS ROG Ally gamepad support lands in hid-asus
Denis Benato's v7 series brings years of out-of-tree Ally controller work into the mainline ASUS HID driver.
BPF LSM gains atomic xattr labeling at inode creation
A bpf-next series lets BPF security programs label new files before they become visible, and closes a verifier hole that allowed trusted-pointer forgery.
KVM arm64 gets basic plumbing for Arm CCA Realms
Arm posts the eighteenth revision of structural KVM changes for confidential Realm VMs, still short of a runnable guest.
Linux MM drops PG_private to free a flag bit for folios
Zi Yan's patchset replaces the page flag with pointer checks so a scarce bit can become PG_folio.
Linux kernel gains in-kernel QUIC transport infrastructure
A netdev series from Xin Long adds core socket, stream, path, and crypto building blocks so subsystems and apps can use QUIC without userspace protocol stacks.
RFC shards procfs inode lists to cut lock storms on big boxes
Huang Shijie reports a 50% Hadoop speedup on a 384-CPU Hygon system after the global procfs inode lock fell from a 90% hotspot to about 1%.
Kbuild series cuts Linux kernel build times by up to 90%
Lorenzo Stoakes targets single-threaded bottlenecks in kallsyms, modpost, nm, and make dependency checks.
NVIDIA posts vGPU manager series for nova-core kernel driver
A 32-patch v2 submission adds host-side creation, VRAM layout, and GSP plugin control for NVIDIA virtual GPUs on Linux.
Rust Binder prepares to retire its C twin as kernel rewrites move past experiment status
Binder deletion, a Rust-only SPDM requester, and unconditional per VMA locks together shift the argument from whether Rust belongs in the kernel to what happens when a Rust implementation becomes the one that wins.
Rust Binder parity makes C removal a real choice
A push to delete the legacy C Binder driver, a Rust SPDM requester for untrusted device auth, and unconditional VMA locks together force the kernel to decide whether dual maintenance ends in security-sensitive paths.
Linux drops legacy C Binder driver for Rust rewrite
Google maintainers say the 15-year-old IPC code is too fragile to keep, and the Rust port is already shipping on Android.
Stable kernel fixes AF_XDP TOCTOU race in TX checksum path
A malicious process could overwrite shared UMEM metadata between check and use, bypassing bounds validation.
Samsung RFC pitches Rust UFS driver that skips SCSI midlayer
Maintainers warn the design duplicates midlayer work and may struggle for UFS contributor adoption.
Linux fixes SRv6 decap flaw causing IPv6 out-of-bounds read
CVE-2026-80976 covers stale outer-packet metadata left on the inner packet after Segment Routing decapsulation, reachable by an unprivileged local user.
MGLRU RFC adds frequency-guided promotion, claims 10-40% gains
Kairui Song's series promotes hot folios on access, fixes PSI and workingset tracking, and stabilizes active/inactive stats while freeing one page flag bit.
Kernel fixes UAFs in POSIX CPU timers on non-leader exec
TID swaps left timer PID references pointing at the wrong task, corrupting signal lists and freeing still-queued structures.
Proxy execution and sched_ext move toward coexistence
Andrea Righi’s v13 series would end the build-time ban that forced kernels to pick one feature or the other.
BPF verifier patches close gotox DoS and register-leak paths
Indirect-jump handling could stall loading for hours and, on a CFG mismatch, leave callee-saved registers under BPF control.
Writeback drain stalls Tasks-RCU, panics hosts on BPF detach
Cgroup writeback cleanup can run for minutes without a Tasks-RCU quiescent state on lazy-preempt kernels, blocking ftrace and BPF unlinks until the hung-task detector fires.
Linux MM series lets folios linger on per-CPU batches
Hugh Dickins's 26-patch rework drops most lru_add_drain calls after years of attempts, aiming to ease lruvec contention and watchdog stalls.
Linux plugs UAF holes in POSIX CPU timers on non-leader exec
Fixes stop list corruption and premature frees when a non-leader thread execs and TIDs are swapped under live timers.
Linux gains first USB4/Thunderbolt path on Apple M1/M2/M3
Sven Peter’s 22-patch series brings ACIO host-router drivers and device-tree wiring so Type-C ports can run USB4 tunnels on Apple Silicon.
BPF gains kfunc to drive proactive memcg reclaim
A sleepable SYSCALL-only helper lets policy programs reclaim from chosen cgroups without writing memory.reclaim.
BPF verifier fixed to stop false non-NULL pointer inference
Several paths let programs pass verification then fault on a null dereference at runtime.
DRM scheduler fence UAF still open after two driver CVEs
A core use-after-free in timeline-name handling still hits amdxdna, nouveau, and msm, and a proposed cache fix was pulled after lifetime objections.
Kernel fixes ethtool ntuple dumps that overflowed heap for any user
Three drivers ignored the caller buffer limit on GRXCLSRLALL, turning admin-installed flow rules into an unprivileged OOB write or null deref.
Ext4 buffered I/O shifts from buffer_head to iomap
Zhang Yi posts v6 of a 31-patch series that modernizes regular-file buffered reads and writes while reworking EOF and journal ordering.
x86 kernel bug dropped dirty bit, silently losing THP data
A pmd_modify() mask error since Linux 6.6 could free rewritten huge pages under reclaim, and Polars users hit it in production.
Arm64 adopts generic syscall entry in the Linux kernel
A long-running conversion brings AArch64 in line with x86 and RISC-V, shrinking arch-specific tracing code and unlocking shared syscall features.
util-linux 2.41.6 fixes three CVEs in mount, nsenter, unshare
The point release stops failed mount helpers from still running privileged post-mount hooks, closes a local TOCTOU on source paths, and seals fd leaks plus a leftover wall/write hostname injection.
Kernel makes page-table freeing RCU-safe on every architecture
Lorenzo Stoakes finishes the conversion so lockless RCU page-table walks become safe kernel-wide.
Linux TCP fixes race UAFs when sockets flip listen and disconnect
connect(AF_UNSPEC), listen(), and IPV6_ADDRFORM left request sockets and parent state that concurrent paths could free while still in use.
Linux net stack gains fwnode PCS API for external SerDes blocks
Phylink takes ownership of PCS selection as SoCs put coding sublayers outside the MAC, with Airoha AN7581 as the first in-tree consumer.
rtl8723bs WPS copy bug allows remote stack overflow on scan
A proposed fix for attacker-controlled beacon attributes still drew maintainer objections over correctness and testing.
IBM posts KVM series to run arm64 guests on s390 hosts
A seventh-round patch set wires arm64 KVM code into s390 via shared markers and a new SAE instruction for hardware-accelerated guests.
RISC-V IOMMU gains MSI remapping, default DMA-IOMMU, and VFIO
A redesigned MSI path lets 64-bit RISC-V translate interrupt targets like DMA, unlocking default IOMMU paging and userspace device assignment.
BPF plugs three NULL derefs in BTF type show paths
Key-less hash map dumps and bpf_snprintf_btf() on void or var types could oops the kernel; Jiayuan Chen restores rejections and safe placeholders.
cfg80211 validates WEXT IE buffers to stop OOB reads
A syzbot-found flaw let malformed wireless Information Elements crash the kernel on connect; the fix is rolling through stable trees.
Kernel clamps qdisc quantum paths that let admins soft-lock hosts
Eight traffic-control schedulers still allowed tiny quanta after setup, reopening a deficit-loop DoS under the qdisc lock.
Kernel fix breaks vmalloc livelock under memory pressure
A circular lock dependency in the vmap purge path could stall the whole system when reclaim and purge work collided.
DRM scheduler fix closes unprivileged GPU fence UAF read
A core lifetime bug let userspace read freed scheduler memory via exported fences in amdxdna, nouveau, and msm.
Confidential VMs force KVM to pick sides on attestation and trust
Arm CCA realms and TDX quote plumbing are no longer vendor demos; they are mainline ABI fights over roots of trust, hardware gaps, and how much attestation the hypervisor should own.
Kernel trusted-keys path hardens TPM1 seal and HMAC checks
Forged TPM 1.x replies could overflow a fixed-size blob buffer or skip response authentication entirely.
Linux kernel panics on GSO fragments after IP reassembly
CVE-2026-80590 lets an unprivileged user trigger a BUG_ON in skb_segment via tap or virtio paths that keep GSO metadata on defragmented packets.
tmpfs casefold option leaked Unicode maps, enabling local DoS
Unprivileged users could exhaust kernel memory by repeatedly setting the casefold mount option on tmpfs.
Kernel reverts IRQ guard switch after Syzbot finds nested lock hazards
Refcounted interrupt disable lands for safer nesting and Rust SpinLockIrq, but wiring it into scoped cleanup guards is rolled back until stronger tooling exists.
Kernel user_events fork path fixed for use-after-free
A failed memory allocation during process duplication could free tracing state still held by the parent.