Linux gains initial USB4 support on Apple M1, M2, and M3
A mainline patch series brings first Thunderbolt host-router bring-up to Apple Silicon, limited for now to XDomain links and USB3 tunnels.
By oopsA mainline patch series brings first Thunderbolt host-router bring-up to Apple Silicon, limited for now to XDomain links and USB3 tunnels.
By oopsEight traffic-control schedulers still allowed tiny quanta after setup, reopening a deficit-loop DoS under the qdisc lock.
By kexecA circular lock dependency in the vmap purge path could stall the whole system when reclaim and purge work collided.
By kexecA core lifetime bug let userspace read freed scheduler memory via exported fences in amdxdna, nouveau, and msm.
By kexecForged TPM 1.x replies could overflow a fixed-size blob buffer or skip response authentication entirely.
By kexecCVE-2026-80590 lets an unprivileged user trigger a BUG_ON in skb_segment via tap or virtio paths that keep GSO metadata on defragmented packets.
By kexecUnprivileged users could exhaust kernel memory by repeatedly setting the casefold mount option on tmpfs.
By kexecA failed memory allocation during process duplication could free tracing state still held by the parent.
By kexecAlexey Gladkov’s RFC to replace per-namespace table cloning with sysctl_field descriptors is rejected as visually illegible, type-unsafe noise.
By oopsAlways creating exceptions for ICMP errors stops off-path attackers from probing connected UDP sockets after earlier defenses were bypassed.
By kexecA public fork accelerates routed NAT on the GL.iNet GL-B3000 without Qualcomm’s proprietary datapath stack, leaving the CPU mostly idle.
By chrootFlaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpitA 16-year-old lost-wakeup race left processes unkillable after brief SMBus and similar contention, reachable from ordinary sensor reads.
By oopsOverflows in fq, fq_codel, fq_pie, hhf, and sfq could hang dequeue loops or NULL-deref on drop.
By oopsA Meta engineer’s patches rate-limit the log spam and turn permanent swap PTE corruption into SIGBUS instead of an infinite retry.
By oopsResearcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT.
By tarpitMaintainers will disable the config option first, with full removal planned after this year's final LTS kernel unless users object.
By kexecNine patches harden hp-bioscfg against out-of-bounds memory access and broken ACPI attribute parsing on HP machines.
By kexecA Clang 21 change that drops landing pads on static functions breaks PLT branches from livepatch modules, so the kernel turns BTI off until the toolchain is fixed.
By oopsThe stable update closes symlink and path-traversal flaws that broke app isolation, with CVE IDs still pending.
By tarpitMissing file_operations ownership in Rust DRM and misc helpers let the kernel call into unloaded code after rmmod.
By renderAndrea Righi's series ends a build-time mutual exclusion so one kernel can ship both features and let BPF schedulers opt in at runtime.
By kexecGit, GCC, and Linux staging maintainers are independently rejecting or tightly regulating AI-assisted contributions, turning copyright risk, review load, and the fate of new-contributor pipelines into a shared governance fight.
By rvalueA Hansen/Baghdasaryan series drops architecture guards so binder and TCP paths can stop falling back to mmap_lock.
By kexecA net-next series extends kernel TLS device offload beyond TLS 1.2, with full rekey support on capable Mellanox NICs.
By kexecA config rename left the CVE-2026-68480 fix inert on the long-term 6.6 series until corrected patches land.
By oopsCVE-2026-64561 corrupts host shadow pages from untrusted guests when nested virtualization is exposed, especially on multi-tenant clouds.
By tarpitA use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.
By tarpitARM64 this_cpu_* optimization RFC hits a hard architectural wall over divergent kernel page tables.
By oopsDirect reclaim after MADV_DONTNEED could free a page table while leaving a stale paging-structure cache entry.
By oopsOmitted commits from a 2024 pipapo series leave use-after-free and double-free bugs in 6.6.y and older trees.
By kexecGreg Kroah-Hartman says automated cleanups defeat the subsystem's role as a training ground for new developers.
By kexecSteven Price’s 45-patch series wires Linux KVM to the Realm Management Monitor so hosts can run protected Arm guests.
By kexecUnchecked endpoint sizes and debug dumps left the Intel USB-to-I2C bridge open to memory corruption, hangs, and log leaks.
By kexecCollabora patches target 4K at 60 Hz on RK3576 and RK3588 and refactor how HDMI connectors declare their capabilities.
By renderDistributions can ship one kernel with both features and let BPF schedulers opt in at runtime.
By kexecDavid Woodhouse’s v7 series fixes long-standing guest timekeeping bugs and adds APIs so live migration can preserve the TSC-to-kvmclock relationship.
By oopsCVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.
By nonceJohn Garry's v5 series folds multipath block devices into the SCSI core, driven by ALUA path state and unique VPD identities.
By oopsA kernel series lets sandbox supervisors feed immutable syscall arguments into uncooperative targets without a trusted setup window.
By oopsDynamic hard_header_len updates raced with lockless TX paths; macvlan-on-VLAN shows a related headroom gap.
By kexecA new page-table helper lets multi-size THP stay available on CPUs that cannot back traditional PMD leaves.
By oopsTwo heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.
By tarpitA kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.
By tarpitGreg Kroah-Hartman and Jonathan Corbet say even non-generative AI code review of the xillybus driver must be credited.
By kexecGregory Price's v5 patchset flips device-backed memory from fully fungible to opt-in kernel services.
By kexecA flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.
By nonce