CISA has added three Linux kernel security flaws to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting them in the wild. The bugs include CVE-2025-39964, a 14-year-old race condition in the AF_ALG crypto socket interface; CVE-2026-53266, an out-of-bounds write in ebtables SNAT; and CVE-2025-39682, a flaw in the kernel's TLS receive path. Federal agencies were ordered to patch these by end of day, though CISA has not disclosed details on the attackers or specific incidents.
bleepingcomputer.com
· 2026-09-21
A reviewer shares detailed impressions of Paul E. McKenney's open-access book 'Is Parallel Programming Hard, And, If So, What Can You Do About It?', tracing how attending the 2026 Software Should Work conference and conversations with Fil-C creator Filip Pizlo sparked renewed interest in concurrency after a period working with TLA+ and a failed attempt to learn Lean. The piece recounts the reviewer's background before diving into reactions to McKenney's material on synchronization and concurrent programming.
ahelwer.ca
· 2026-09-21
An analysis traces the evolution of memory allocation from stack-based schemes to dynamic linked-list heaps, garbage collection, and jemalloc's 2006 introduction of 'arenas' for NUMA and multi-core memory management. It notes that standard malloc() implementations serialize concurrent allocation requests, causing multithreaded applications to slow down rather than scale as processor counts increase.
egbert.net
· 2026-09-15
The team behind the open-source Bomfather eBPF security agent found that the costliest part of their file-access enforcement wasn't applying allow/deny decisions, but repeatedly walking parent directories to determine which path-based policy applied to a given file. By caching the resolved policy per inode instead of recalculating it on every file open, they cut kernel-side CPU overhead by roughly 90%, particularly benefiting workloads like databases that repeatedly access the same file paths.
nathannaveen.dev
· 2026-09-14
A security researcher describes the practical difficulty of confirming and reproducing race condition bugs in software, particularly the Linux kernel. Current techniques include manually inserting delay calls into kernel code to force specific thread interleavings, or using DTrace probes on macOS and Windows, both of which are slow and require trial and error.
projectzero.google
· 2026-09-09
A new project called BPF Capsule compiles large C programs, including a complete DOOM implementation, into standard eBPF bytecode that passes the unmodified Linux verifier and JIT. The system runs game initialization, logic, and rendering entirely inside the kernel, with userspace only supplying the WAD file and keyboard input and receiving back a finished framebuffer each tick. It works without kernel patches or a separate virtual machine, targeting kernels as old as Linux 5.15 on both x86-64 and arm64.
ayles.github.io
· 2026-09-09
AMD engineers are increasing efforts to integrate the Rust programming language deeper into their GPU software, aiming to improve memory safety and reliability across drivers and related components. The move mirrors similar work at NVIDIA, which has been developing its own Rust-based Nova Linux kernel driver.
developers.slashdot.org
· 2026-09-08
A technical write-up explains how libzmq now supports AF_VSOCK, the Linux socket address family used for VM-to-hypervisor communication, originally developed by VMware as VMCI. The piece notes that while several languages already offer low-level AF_VSOCK bindings, no higher-level abstraction existed until this libzmq integration, which lets developers use familiar ZeroMQ patterns instead of manually handling raw socket calls.
blog.remijouan.net
· 2026-09-07
Asahi Linux developers have officially declared support for Apple's M3, M3 Pro, and M3 Max Macs, bringing them close to parity with earlier M1/M2 support—except for the Mac Studio M3 Ultra, which remains unsupported. Key limitations remain, including weak GPU acceleration, no sleep mode, and non-functional HDMI ports on M3 MacBooks due to missing DCP support.
phoronix.com
· 2026-09-06
A developer documented the process of bringing up the Linux kernel on a new platform by writing a lightweight emulator for a RISC-V CPU rather than using real hardware. The emulator, built in roughly 2000 lines of C++ and implementing the RV32IMA instruction set, provides just enough hardware simulation—MMU support, RAM, an SBI interface, a system timer, and a WD8250-based UART—for Linux to boot. The full source is published on GitHub under WerWolv/riscv-emulator.
werwolv.net
· 2026-09-03
Chinese AI firm Z.ai's GLM-5.3 model helped find over 1,000 critical vulnerabilities in open-source projects including the Linux kernel, adding to a wave of AI-discovered bugs this year. Kernel maintainer Greg Kroah-Hartman showed data indicating CVEs fixed per kernel release have surged from about 500 to nearly 2,000 as AI code-review tools improve.
techspot.com
· 2026-09-02
A technical post explains intrusive linked lists, a linked-list variant where the 'next' pointer is embedded directly inside the data structure being linked rather than stored in a separate wrapper node. It walks through how to construct such a list in C, including how to recover the address of a containing object by subtracting the offset of its embedded list member.
data-structures-in-practice.com
· 2026-08-31