← Back to archive

Daily update · Oct 4–5, 2026

Linux 7.3-rc6: perf, x86, and i2c fixes

Release candidate includes a perf text-poke security fix, an x86 hugetlb alignment fix, and SMBus PEC corrections.

In brief

Linux 7.3-rc6 is out, with fixes across perf, x86 memory management, i2c, and futex. Highlights include closing a KASLR bypass via perf text-poke events and preventing a hugetlb alignment crash on some AMD systems.

Release

Linux 7.3-rc6

Sixth release candidate for the 7.3 kernel cycle.

Why it matters: Testing milestone for the upcoming 7.3 stable release.

a90ee4305c4a

Bug fixes

i2c-xiic: fix SMBus block reads with PEC

The xiic driver recalculated the receive length from the device's length byte but dropped the PEC byte the SMBus core had accounted for. A related threshold bug fired RX_FULL before the final byte was buffered, and the done path overwrote msg->len, causing the PEC check to read from the wrong offset.

Why it matters: SMBus block reads with PEC no longer fail with -EBADMSG on Xilinx I2C controllers.

b7e6df2f52ede6fe3ea04f01840d8acc8792

i2c-at91: release DMA channels on probe defer

When probe defers after DMA channels are requested, they were not released, leaking channels on every retry.

Why it matters: Fixes a resource leak during deferred probing.

c98bf3b86609

x86/mm: fix hugetlb alignment on AMD F15h

ASLR alignment bits were applied to hugetlb mappings, producing addresses not aligned to the huge page boundary and tripping a BUG_ON during unmap.

Why it matters: Prevents a crash on affected AMD systems using hugetlb mappings.

d2457a7e2727

x86/mm: drop PMD copy in page-table free path

A PMD page copy in the free path took mmap_read_lock and could deadlock with reclaim; the copy was meant to avoid hardware setting Accessed on unreachable entries.

Why it matters: Removes a potential deadlock when kswapd shrinks GPU memory pools.

e3ee38c1bc0b

x86/uapi: guard 32-bit register offset macros

Register offset macros like EBX were unguarded and could collide with userspace identifiers; now guarded for assembler/frame-offset use.

Why it matters: Userspace no longer needs to worry about include ordering with these short macro names.

a661c34fe693

hrtimer: fix TIF_HRTIMER_REARM mask usage

The code used the bit number instead of the mask, clearing unrelated TIF flags and leaving task work pending.

Why it matters: Task work queued from hrtimer callbacks now runs promptly instead of waiting for a syscall.

28fa9af353be

perf: fix race between exit and pending task

During exec, perf_event_exit_task could race with perf_pending_task, triggering a WARN_ON_ONCE because the context task check failed.

Why it matters: Removes a spurious warning during exec with perf events.

ffb684f2aa14

perf: replace partial header init with full init

perf_event_header__init_id mutated header size in place; some sideband callbacks didn't restore it, so later events got records with incorrect sizes.

Why it matters: Corrects PERF_RECORD_KSYMBOL/BPF/TEXT_POKE records when multiple events are active.

b9d1fdc6f4ac

perf: require kernel access for text poke events

text_poke events could be opened without kernel access and leaked kernel instruction addresses, defeating KASLR.

Why it matters: Unprivileged users can no longer infer the kernel text base via text poke events.

357e8a77a501

irq: make refcount interrupt KUnit test optional

The refcount_interrupt_test ran automatically when KUnit was enabled; it now has its own config option.

Why it matters: Avoids unexpected test runs during boot for KUnit users.

26f6b6357b1b

futex: fix use-after-free on private hash resize

A race in the private hash resize could allow a reader to hold a pointer to the old hash after it was freed.

Why it matters: Fixes a memory safety bug in futex private hash resizing.

f35e3b578422

Source commits14 entries +
a661c34fe693

{x86,um}/uapi/ptrace: Guard register offset macros with __ASSEMBLER__ or __FRAME_OFFSETS

Nick Desaulniers · Aug 21, 2026 · 3 files

28fa9af353be

hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work

Karl Mehltretter · Sep 19, 2026 · 1 files

ffb684f2aa14

perf: Fix race between perf_event_exit_task() and perf_pending_task()

Luo Gengkun · Sep 20, 2026 · 1 files

d2457a7e2727

x86/mm: Don't apply va_align to hugetlb mappings on AMD F15h

Laurent Wandrebeck · Sep 22, 2026 · 1 files

e3ee38c1bc0b

x86/mm: Drop unnecessary PMD page copy when freeing

Mikhail Gavrilov · Sep 23, 2026 · 1 files

b7e6df2f52ed

i2c: xiic: preserve PEC byte length in SMBus block read setup

Abdurrahman Hussain · Sep 25, 2026 · 1 files

e6fe3ea04f01

i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO

Abdurrahman Hussain · Sep 25, 2026 · 1 files

840d8acc8792

i2c: xiic: don't clobber msg->len to signal block-read completion

Abdurrahman Hussain · Sep 25, 2026 · 1 files

357e8a77a501

perf: Require kernel access for text poke events

Zhengchuan Liang · Sep 28, 2026 · 1 files

c98bf3b86609

i2c: at91: release DMA channels when probe defers

Hongjian Dai · Sep 29, 2026 · 1 files

b9d1fdc6f4ac

perf: Replace perf_event_header__init_id with full header init

Ian Rogers · Sep 29, 2026 · 4 files

26f6b6357b1b

irq: Make refcount_interrupt kunit test selectable

Kuan-Wei Chiu · Oct 1, 2026 · 2 files

f35e3b578422

futex: Fix private hash use-after-free on resize

Chris Mason · Oct 1, 2026 · 1 files

a90ee4305c4a

Linux 7.3-rc6

Linus Torvalds · Oct 4, 2026 · 1 files