A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.
By tarpit
Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.
By tarpit
A single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.
By nonce
CVE-2026-53090 addressed incomplete failure-path analysis that could let unsafe programs pass verification.
By kexec
A flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.
By nonce
A dense run of USB, display, NIC, and UEFI fixes shows the project still treating guest and migration input as untrusted, while the underlying C surface remains large enough that clouds must keep asking how much trust that buys them.
By cronjob