QEMU CVEs and AI policy, PostgreSQL corruption and RI revert
QEMU traffic centered on smartcard and VGA memory-safety fixes plus policy and architecture series. PostgreSQL hackers addressed heap tuple corruption and a proposed stable-branch revert of RI fast-path batching.
QEMU smartcard pull with three CVEs
A QEMU maintainer posted a 27-part git pull request covering smartcard fixes that include three CVEs and multiple specification-compliance corrections in the USB CCID smartcard device. The series targets guest-visible USB smartcard emulation. Operators and packagers should treat the security and compliance changes as high priority.
CCID bulk-in ring OOB read (CVE-2026-18204)
A QEMU patch fixes CVE-2026-18204, an out-of-bounds read in the USB CCID smartcard device pending bulk-in ring. Two participants discussed the change. The fix closes a memory-safety hole in the emulated smartcard reader path.
VGA OOB writes after console surface resize
A QEMU patch corrects out-of-bounds writes in vga_draw_blank and graphic drawing when virtio-gpu replaces a shared QemuConsole surface. Two participants exchanged the patch. The change prevents memory corruption after external surface resize.
QEMU AI-generated contribution policy v4
QEMU circulated a fourth revision of a proposed policy that relaxes a blanket ban on AI-generated contributions, adds attestation trailers, and requires pre-approval for large submissions. Seven participants discussed the docs and AGENTS.md changes. The shift affects how contributors prepare and how maintainers review future patches.
PostgreSQL ctid corruption in ExecForceStoreHeapTuple
A pgsql-hackers patch fixes missing tts_tid in ExecForceStoreHeapTuple, which could produce ctid corruption, unexpected table extension, and invalid pages on FOR UPDATE after GiST KNN scans. Five participants examined the bug. The fix restores correct locked heap access after those index paths.
ARM64 guests for QEMU MSHV accelerator
A sixth revision of a 14-part series adds ARM64 guest support to the QEMU MSHV accelerator via an x86 refactor and a new ARM backend for vCPU, MMIO, and vGIC. The series expands Microsoft Hypervisor acceleration beyond x86. Builders targeting MSHV on ARM will care about the backend split.
Single-binary multi-target qemu-system
A 114-commit third revision proposes linking multiple QEMU targets into one qemu-system binary, with widespread symbol, QOM, and TypeInfo changes. Six participants debated the approach. The work would reshape multi-architecture packaging and the internal type system.
Revert RI fast-path batching from PostgreSQL 19 stable
PostgreSQL developers proposed reverting RI fast-path batching from REL_19_STABLE over trigger and subtransaction interaction risks while retaining it in master. Five participants weighed the stability trade-off. The outcome decides whether the optimization ships in the next stable release.