Linux Weekly News: Key Stories Ahead of This Week

A dense week of kernel work, distro releases, desktop and ARM laptop news, plus some strong security and tooling stories for Linux users and admins.

:top_arrow: Top Stories

  • Linux 7.2.8 and 7.3-rc5 released — kernel.org lists 7.2.8 as the latest stable kernel (released 2026-09-25) and 7.3-rc5 as the current mainline test release (2026-09-27), bringing another round of fixes ahead of the expected 18 October 7.3 final. Anyone tracking stable for production should be looking at 7.2.8 (or their distro’s backports), while testers and driver developers can start validating against 7.3-rc5.

  • Qualcomm details Linux support for Snapdragon X2 laptops — Qualcomm’s summit materials and an early developer preview covered by It’s FOSS show Debian 13 “Trixie” plus a custom kernel running on Snapdragon X2, with mainline-oriented work on USB/PCIe, Mesa (Freedreno/Turnip/Rusticl), FastRPC and Hexagon NPU offload. This matters for anyone eyeing ARM64 laptops: Qualcomm is explicitly courting kernel and distro maintainers now instead of shipping opaque vendor kernels.

  • Ubuntu tightens kernel SRU cadence to respond to AI-driven CVE discovery — Canonical is moving from a split 4‑week/2‑week kernel SRU schedule to a single 2‑week cycle, with each cycle overlapping so certified kernels land weekly and -proposed builds available earlier. For Ubuntu admins this means security fixes (especially for kernel CVEs increasingly found by automated tooling) should land faster, but you may want to revisit how aggressively you consume -proposed in your own CI.

  • Linux support coming to Snapdragon X2 series from the vendor side — GamingOnLinux highlights Qualcomm’s announcement that Snapdragon X2 Series for “Arm PCs” will officially support Linux, aligning with their Debian-based preview images and upstream driver work. This is a key signal for desktop Linux on ARM: vendor-backed GPU, NPU and power-management support is what turns “hackable dev kit” hardware into something distros can actually target.

  • DAWO: Dutch government building a NixOS-based sovereign desktop stack — The Netherlands is rolling out DAWO (Digitaal Autonome Werkomgeving Overheid), a standardized government workstation built on NixOS, with three state IT providers (SSC‑ICT, DICTU, DUO‑ICT) executing the mandate. For anyone in public-sector IT or EU compliance this is another concrete example of a government betting on reproducible, vendor-neutral Linux desktops after sanctions disrupted access to US-hosted services.

:shield: Security Watch

  • A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, DiagSpill — oss-security documents four separate local privilege escalations in Linux networking components (including AF_PACKET IPv6 extension headers, PPPoE and TUN/TAP handling) with proof-of-concept exploits. Anyone running multi-user systems, containers, or untrusted workloads on Linux should track their distro’s kernel updates closely in the coming weeks as fixes for these LPEs are integrated.

  • AF_ALG local root escalation story with $113,337 bounty — IDN Security’s write-up explains how a bug in the AF_ALG crypto socket interface allowed local privilege escalation and netted a US$113,337 reward, walking through the vulnerability, exploitation, and fix. Operators who enable AF_ALG (often via cryptographic or offload tooling) should confirm they’re on a kernel including the patch level described in the research.

  • House of Apple 2 heap exploitation on modern glibc — This technical deep-dive revisits the “House of Apple 2” allocator exploitation technique against current glibc, mapping out mitigations and remaining attack surfaces. While aimed at exploit developers, it’s a useful read for distro security teams and performance engineers relying on glibc’s malloc behavior in hardened builds.

:package: Releases & Updates

  • Linux 7.2.8 stable — The 7.2.8 point release dated 2026-09-25 rolls up the latest stable fixes, and kernel.org now labels 7.1.13 as EOL, so long-term users should be moving to 7.2.x or another supported series.

  • Linux 7.3-rc5 — Linus Torvalds tagged 7.3-rc5 on 2026-09-27 as “another large RC”, with kernel.org noting it as the current mainline snapshot as the tree stabilizes toward October.

  • Samba 4.25 released — Samba 4.25 introduces experimental SMB3 persistent handles and other improvements, giving file servers and mixed Windows/Linux shops more resilience for long-lived connections when clients or network paths flap.

  • GDB 18.1 debugger — GDB 18.1 brings better Windows support plus ongoing improvements for C/C++, Fortran, Rust, Go and Ada debugging, which matters for cross-platform projects and toolchain integrators shipping up-to-date debuggers.

  • openSUSE 16.1-rc — The openSUSE project published a 16.1 release candidate, continuing its mission to provide an easy-to-obtain, community-driven distro ahead of the final 16.1 release for both desktop and server users.

  • MagOS 2025_20260925 snapshot — This ROSA-based desktop distro updated its 2025 build on 2026‑09‑25, delivering refreshed KDE Plasma and LXQt-based images for Russian and international users who want a Mandriva-descended system with extra hardware modules.

:hammer_and_wrench: Worth Reading & Trying

  • “Containers Are No Longer a Security Boundary” — This Lobsters-linked research argues that Linux containers should not be treated as strong isolation, outlining specific kernel attack surfaces that remain exposed and what that implies for multi-tenant or “shared root” environments.

  • Drop: a rootless Linux sandbox with gVisor support — A Show HN project, Drop uses Linux namespaces plus optional gVisor to give each “environment” its own disposable home directory with selected config mounts, letting developers run untrusted tools without ceding full access to their real $HOME.

  • Self-hosting behind CGNAT — This Lobsters article walks through practical approaches to hosting services from a connection stuck behind carrier-grade NAT, useful for homelabbers dealing with ISP restrictions.

  • Tuning a server for benchmarking — Another solid piece from the same author on how to configure Linux servers (CPU governor, IRQ affinities, kernel parameters) to get reliable, comparable benchmark numbers instead of noisy one-off runs.

  • “Containers and servers aren’t enough: Portainer CE frozen at 2.45 LTS” — It’s FOSS explains why Portainer Community Edition will stay on 2.45 LTS while 3.x goes Kubernetes-first with proprietary tooling, and surveys alternatives like Komodo and Arcane for users who want an actively developed FOSS container UI.

:penguin: From LinuxBlog.io

Share what you’re upgrading, testing, or worried about from this week’s news in the replies below.


Our community remains free of banner ads thanks to our partnership with Better Stack.

Better Stack offers infrastructure observability services, uptime monitoring, logging, incident management, and a free tier worth checking out. Visit: betterstack.com

4 Likes