Daily update · Oct 4–5, 2026
Linux 7.3-rc6: perf, x86, and i2c fixes
Release candidate includes a perf text-poke security fix, an x86 hugetlb alignment fix, and SMBus PEC corrections.
In brief
Linux 7.3-rc6 is out, with fixes across perf, x86 memory management, i2c, and futex. Highlights include closing a KASLR bypass via perf text-poke events and preventing a hugetlb alignment crash on some AMD systems.
Release
Linux 7.3-rc6
Sixth release candidate for the 7.3 kernel cycle.
Why it matters: Testing milestone for the upcoming 7.3 stable release.
Bug fixes
i2c-xiic: fix SMBus block reads with PEC
The xiic driver recalculated the receive length from the device's length byte but dropped the PEC byte the SMBus core had accounted for. A related threshold bug fired RX_FULL before the final byte was buffered, and the done path overwrote msg->len, causing the PEC check to read from the wrong offset.
Why it matters: SMBus block reads with PEC no longer fail with -EBADMSG on Xilinx I2C controllers.
i2c-at91: release DMA channels on probe defer
When probe defers after DMA channels are requested, they were not released, leaking channels on every retry.
Why it matters: Fixes a resource leak during deferred probing.
x86/mm: fix hugetlb alignment on AMD F15h
ASLR alignment bits were applied to hugetlb mappings, producing addresses not aligned to the huge page boundary and tripping a BUG_ON during unmap.
Why it matters: Prevents a crash on affected AMD systems using hugetlb mappings.
x86/mm: drop PMD copy in page-table free path
A PMD page copy in the free path took mmap_read_lock and could deadlock with reclaim; the copy was meant to avoid hardware setting Accessed on unreachable entries.
Why it matters: Removes a potential deadlock when kswapd shrinks GPU memory pools.
x86/uapi: guard 32-bit register offset macros
Register offset macros like EBX were unguarded and could collide with userspace identifiers; now guarded for assembler/frame-offset use.
Why it matters: Userspace no longer needs to worry about include ordering with these short macro names.
hrtimer: fix TIF_HRTIMER_REARM mask usage
The code used the bit number instead of the mask, clearing unrelated TIF flags and leaving task work pending.
Why it matters: Task work queued from hrtimer callbacks now runs promptly instead of waiting for a syscall.
perf: fix race between exit and pending task
During exec, perf_event_exit_task could race with perf_pending_task, triggering a WARN_ON_ONCE because the context task check failed.
Why it matters: Removes a spurious warning during exec with perf events.
perf: replace partial header init with full init
perf_event_header__init_id mutated header size in place; some sideband callbacks didn't restore it, so later events got records with incorrect sizes.
Why it matters: Corrects PERF_RECORD_KSYMBOL/BPF/TEXT_POKE records when multiple events are active.
perf: require kernel access for text poke events
text_poke events could be opened without kernel access and leaked kernel instruction addresses, defeating KASLR.
Why it matters: Unprivileged users can no longer infer the kernel text base via text poke events.
irq: make refcount interrupt KUnit test optional
The refcount_interrupt_test ran automatically when KUnit was enabled; it now has its own config option.
Why it matters: Avoids unexpected test runs during boot for KUnit users.
futex: fix use-after-free on private hash resize
A race in the private hash resize could allow a reader to hold a pointer to the old hash after it was freed.
Why it matters: Fixes a memory safety bug in futex private hash resizing.
Source commits14 entries +
{x86,um}/uapi/ptrace: Guard register offset macros with __ASSEMBLER__ or __FRAME_OFFSETS
Nick Desaulniers · Aug 21, 2026 · 3 files
hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
Karl Mehltretter · Sep 19, 2026 · 1 files
perf: Fix race between perf_event_exit_task() and perf_pending_task()
Luo Gengkun · Sep 20, 2026 · 1 files
x86/mm: Don't apply va_align to hugetlb mappings on AMD F15h
Laurent Wandrebeck · Sep 22, 2026 · 1 files
x86/mm: Drop unnecessary PMD page copy when freeing
Mikhail Gavrilov · Sep 23, 2026 · 1 files
i2c: xiic: preserve PEC byte length in SMBus block read setup
Abdurrahman Hussain · Sep 25, 2026 · 1 files
i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO
Abdurrahman Hussain · Sep 25, 2026 · 1 files
i2c: xiic: don't clobber msg->len to signal block-read completion
Abdurrahman Hussain · Sep 25, 2026 · 1 files
perf: Require kernel access for text poke events
Zhengchuan Liang · Sep 28, 2026 · 1 files
i2c: at91: release DMA channels when probe defers
Hongjian Dai · Sep 29, 2026 · 1 files
perf: Replace perf_event_header__init_id with full header init
Ian Rogers · Sep 29, 2026 · 4 files
irq: Make refcount_interrupt kunit test selectable
Kuan-Wei Chiu · Oct 1, 2026 · 2 files
futex: Fix private hash use-after-free on resize
Chris Mason · Oct 1, 2026 · 1 files
Linux 7.3-rc6
Linus Torvalds · Oct 4, 2026 · 1 files