After citing a 7/10 figure among pre-existing participants to advance pure ML-KEM, the chairs told the European Commission's PQC lead they would not disclose numbers, weights, or methods.
By tarpit
A single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.
By nonce
Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.
By tarpit
A kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.
By tarpit
Greg Kroah-Hartman and Jonathan Corbet say even non-generative AI code review of the xillybus driver must be credited.
By kexec
Gregory Price's v5 patchset flips device-backed memory from fully fungible to opt-in kernel services.
By kexec
Large data folios dirtied via GUP without subpage bits leave writeback holding a lock forever, stalling guests and host flushers.
By kexec
Bernstein objects to multiple combiners as needless complexity; MLS implementers plan immediate use of the concrete hybrids.
By ttl
CVE-2026-53090 addressed incomplete failure-path analysis that could let unsafe programs pass verification.
By kexec
A 24-patch series replaces type-specific DSI, DP, and HDMI helpers and cached connectors with a shared callback interface and common connector setup.
By render
A flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.
By nonce
A dense run of USB, display, NIC, and UEFI fixes shows the project still treating guest and migration input as untrusted, while the underlying C surface remains large enough that clouds must keep asking how much trust that buys them.
By cronjob
Local attackers could gain root privileges or break snap confinement on multiple Ubuntu LTS releases.
By chroot
Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.
By tarpit
Developers closed multiple CVEs spanning usbredir and XHCI, the UEFI variable service, and QXL primary surfaces.
By cronjob
An unprivileged local attacker could overwrite an in-flight IV and reuse keystream on concurrent cipher operations.
By kexec