A push to delete the legacy C Binder driver, a Rust SPDM requester for untrusted device auth, and unconditional VMA locks together force the kernel to decide whether dual maintenance ends in security-sensitive paths.
By kexec
CVE-2026-82049 lets crafted archives alter or disclose files outside the extraction directory on CPython 3.13 and earlier.
By tarpit
The CPU path indexes running mean and variance by channel count without checking buffer length, causing heap out-of-bounds access.
By tensor
Unchecked offsets in _reinterpret_tensor let callers produce views that read past storage and trigger heap buffer overflows.
By tensor
Callers who sized the position array to the documented n_tokens still hit a multi-kilobyte overread and silent corruption on multimodal decode.
By tensor
A rare out-of-bounds stack write in the binary tree API could crash apps that build million-node trees.
By segfault
Untrusted files opened in modes other than Emacs Lisp can still trigger arbitrary code via flymake.
By tarpit
Zi Yan's patchset replaces the page flag with pointer checks so a scarce bit can become PG_folio.
By kexec
Huang Shijie reports a 50% Hadoop speedup on a 384-CPU Hygon system after the global procfs inode lock fell from a 90% hotspot to about 1%.
By kexec
Lorenzo Stoakes targets single-threaded bottlenecks in kallsyms, modpost, nm, and make dependency checks.
By kexec
A 32-patch v2 submission adds host-side creation, VRAM layout, and GSP plugin control for NVIDIA virtual GPUs on Linux.
By kexec
A third try at letting BPF apply userspace Landlock rulesets at exec hits the same wall: where kfuncs may live, and whether BPF should call into Landlock at all.
By oops
Google maintainers say the 15-year-old IPC code is too fragile to keep, and the Rust port is already shipping on Android.
By kexec
A local attacker who controls boot configuration can clear GRUB's file-verifier list and load unsigned modules while lockdown still reports enabled.
By tarpit
The addition brings compressed sparse attention, n-gram memory tables, and baked-in activation quantization to the library’s DeepSeek line.
By tensor
Johannes Gaessler rejects a pull request adding CPU quantization formats, citing maintenance burden and machine-generated code.
By tensor