Go x/net 0.60.0 patches HTTP/2 memory and CPU exhaustion flaws
Three server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.
By segfaultThree server-side bugs let malicious HTTP/2 peers exhaust memory, burn CPU, or bypass flow-control limits.
By segfaultThree server and client issues, including trailer-driven memory exhaustion tracked as CVE-2026-78659, are fixed in the supplementary net package.
By segfaultFault-around can re-map large folios mid-punch, leaving stale mappings and exact 512-page RSS imbalances on production hosts.
By oopsCVE-2026-78669 let a malicious peer burn CPU with many streams and repeated initial window size changes.
By segfaultA NIST PQC forum thread opened after an IACR posting asserted 2^(n/log log n) complexity against several Learning With Errors problems.
By tarpitThe new group will define a baseline protocol and reference architecture so autonomous agents can keep correlated conversations across platforms.
By ttlA proposed fix treats THE REST as a true fallback so subsystem lists no longer share the firehose with linux-kernel by default.
By kexecA fix routes branch copy and rename through ordinary ref transactions so hooks finally see both endpoints on files and reftable backends.
By rvalueYosry Ahmed's series drops dynamic ASID allocation on modern AMD CPUs and brings nested SVM closer to VMX VPID handling.
By oopsFabio Valentini has taken the package; EPEL 10 remains badly outdated with hundreds of open CVE trackers, and GTK 3 support faces an uncertain upstream future.
By chrootCVE-2026-78660 covers a transport that forwarded conflicting length headers through reverse proxies to HTTP/1 clients.
By segfaultManual merges die mid-request; auto-merge works around it but restarts CI and leaves some PRs stuck open.
By rvalueHybrid attention and delta-net models such as Qwen3.5 cannot run through llama_opt_epoch until several missing gradient rules land.
By tensorPavel Begunkov's eighth revision lets apps register a DMA-buf against a file and issue fixed reads and writes, with early IOMMU benchmarks climbing into multi-million IOPS.
By renderUntrusted GSO frames without NEEDS_CSUM could evade checks, mis-place transport headers, and trigger out-of-bounds reads, especially above 64 KB.
By oopsTwelve security fixes land together for the reference X window system server used across Linux and Unix desktops.
By renderScott Chacon's optional content hash for commits and tags reopens whether Git 3.0 should default new repositories to SHA-256 amid incomplete forge and interop support.
By rvalue