BPF verifier gains widening path for long bounded loops
Alexei Starovoitov’s series stops the verifier from walking every iteration of simple loops, cutting work sharply while keeping today’s accepted programs valid.
By oopsAlexei Starovoitov’s series stops the verifier from walking every iteration of simple loops, cutting work sharply while keeping today’s accepted programs valid.
By oopsLorenzo Stoakes’ 22-patch series attacks single-threaded bottlenecks from toolchain probes and modpost through objtool and module finalisation.
By oopsCVE-2026-2270 lets users with namespace-scoped StatefulSet and ControllerRevision write access create pods outside their namespace.
By cronjobx86-64 and arm64 JITs would get the larger budget; the interpreter and other architectures stay at 512 bytes.
By kexecBIOS-enabled enhanced atomics on some AMD root ports were mangling 64-bit DMA, hitting SATA and NVMe drives on desktop systems.
By oopsPaolo Bonzini’s patches add REX2, 32 GPRs, and new instructions while laying EVEX groundwork without full AVX-512.
By sudoThe ?? and ??= forms would supply defaults only when a value is None, and can be accepted independently of related None-aware access syntax.
By segfaultCVE-2026-76183 lets attackers sidestep authentication rules on WebSocket endpoints across long-supported Tomcat lines.
By tarpitCVE-2026-94422 let apps bypass D-Bus message filters and run code outside the sandbox.
By tarpitA race while building the initial snapshot lets a toast rewrite leave committed column values behind with no error.
By sudoA fill-order versus stride-order mixup in copy_strided lowering overruns CPU buffers under torch.compile with dynamic shapes.
By tensorCVE-2026-93834 addressed a worker-thread path mutation that main-thread readers did not lock against.
By sudoA fourteenth revision unifies fault handling with device-page migration, but automated review flagged livelocks, notifier imbalances, and missing TLB flushes.
By renderYonghong Song’s bpf-next series makes bpf_throw() run compiler-emitted landing pads so resource-owning frames can release locks and values on the way out.
By oopsLast Call on the IETF applicability statement reopenes a fight over whether receivers must be able to take mail without TLS.
By ttlAndrea Righi’s v14 series drops the build-time ban so distributions can ship both features and let BPF schedulers opt in at runtime.
By oopsCVE-2026-95818 lets a local user crash or partially corrupt AT_SECURE binaries on glibc 2.14 through 2.44.
By segfault