Linux 3441 Published by

Greg Kroah-Hartman shipped two stable Linux kernels on the same day: 7.2.10 for the current mainline series and 6.18.56 for this year's LTS release. Both carry the same headline fixes, most importantly a TCP IPv4 use-after-free squashed by Eric Dumazet and a KASLR leak closed through the perf subsystem. Virtualization got heavy emphasis too, with a cluster of KVM/x86 nested-virt memory-safety patches plus an ARM Cortex-A725 erratum workaround shared across both trees. 





Linux kernel 7.2.10 and 6.18.56 land same day with TCP and KASLR fixes

Greg Kroah-Hartman shipped the current mainline stable update and this year's LTS fix today.

Greg Kroah-Hartman doesn't often release two stable kernels at once, so Sunday's double drop is worth a glance. Both hit kernel.org at the same timestamp. One feeds the bleeding-edge mainline crowd. The other keeps the servers that refuse to move.

Kernel

Linux 7.2.10 rides this year's feature series, the one Linus Torvalds shipped August 16, 2026. Linux 6.18.56 is the long-term support release, the workhorse under a lot of data centers since November 30, 2025. They share most fixes, and both are backports from Linus's tree, which is how the stable line is supposed to run.

The headline isn't a new feature. It's two security and stability patches that happen to matter. The bigger one is a TCP IPv4 use-after-free that Eric Dumazet squashed. Under concurrent SYN retransmission or request-socket migration, a child socket could be freed while a SYNACK was still being assembled. That's the textbook bug class you really don't want running in production.

Keep in mind that IPv6 was already safe, since it duplicates socket options. IPv4 was left open, so that's what got patched.

The security fixes that matter

The other notable fix closes a KASLR leak through the perf subsystem. Zhengchuan Liang, Dapeng Mi, and Peter Zijlstra all get credit here. Perf events requesting text-poke records or kernel callchains now need kernel profiling access even when exclude_kernel is set to one. Before this, an unprivileged user could read relocated kernel instruction addresses and defeat kernel address randomization outright.

That's a genuine escape hatch. KASLR is the first line of defense against attackers hunting for kernel code in memory, and it was quietly hole-y.

The changelog for 7.2.10 runs roughly 14,800 lines. Six-point-eight-five-six is a shade smaller at about 13,670 lines. Those numbers are just the surface. The meat lives in networking, virtualization, and a smattering of driver fixes.

This cycle leaned hard on KVM. Sean Christopherson and Paolo Bonzini re-pended GET_NESTED_STATE_PAGES when page acquisition failed, added static calls for hot nested-virtualization paths, and now reject nested capability enablement when virtualization is disabled. On ARM, KVM/arm64 got stage-1 leaf-size treatment for VM_PFNMAP plus fine-grained UNDEFs that no longer trip a spurious warning.

Not cheap to follow, but these are exactly the memory-safety issues that quietly become CVEs. Having both 7.2 and 6.18 LTS carry them is the entire point of a same-day release.

Beyond the headline acts, there's enough to chew on. The Xen netfront driver now drops RX packets with a short Ethernet header, avoiding a BUG() crash in the packet path when cloud backends send malformed frames. The SMB client relaxes a read-lease requirement so interior fallocate calls stop spuriously failing against Windows servers. Minor annoyance, but the kind that makes sysadmins grumble in meetings.

There's also an ARM Cortex-A725 erratum 3821522 workaround shared across both trees, fixing a counter-timing error around the CNT_CYCLES event when CPUs idle in and out of WFE/WFI. Quectel's EG120K-EA modem gained support too, for anyone running the GL.iNet GL-X2000.

Oh, and one housekeeping note before someone in the comments flags it: Linux kernel 7.2.10 is not the same as VirtualBox 7.2.10. Oracle and VMware released that virtualization product in June. They just happen to share a version number. This story is about the kernel. Full stop.

Why the same-day timing matters at all is worth stating plainly. Organizations stuck on LTS 6.18 for stability and early adopters on 7.2 both walk away with the latest fixes together. Security is the through-line, and backporting the TCP, KASLR, and KVM fixes to both trees means long-lived production boxes aren't left exposed while the feature line races ahead.

The 7.2 series that 7.2.10 patches has been doing heavy lifting since August. Cache-aware task scheduling co-locates threads sharing data within the same last-level cache domain. A fairer GPU scheduler built on CFS replaces the old FIFO one. Swap table "Phase IV" reportedly saves roughly 512 MB of RAM when mounting a 1 TB swap device. It reads like a list of performance bets, and most pay off for the right workload.

6.18 LTS is worth a moment too. Greg extended its support window to December 2028 after coordinating with vendor groups, giving you nearly three more years of fixes. That longevity is exactly why the higher point number (56 versus 10) belongs to the older LTS rather than the newer feature release. Production teams plan hardware lifecycles around a kernel they trust won't be abandoned.

There's a detail you won't find in the release notes: 6.18 LTS picked up a fix for AMD gfx1151 instability under local GenAI inference, the kind of thing that bites if you run llama.cpp or ComfyUI on the edge. The AI workload churn has genuinely reshaped what these kernels have to handle, and this line absorbed it without a fresh feature cycle.

Where to grab them

If you're on the 7.2 series, upgrade when it suits you. The boilerplate says all users must upgrade, which is standard stable-tree language rather than a gentle suggestion. Virtualization and cloud deployments benefit most immediately from the TCP, KASLR, and KVM fixes, so those groups might move faster.

Distribution kernels will lag a few days to weeks as they re-test, so build from source or ride a rolling distro if you want the freshest patches. Enterprise distros fold them into their own errata channels eventually.

Linux kernel 7.2.10 released

Linux kernel version 7.2.10 is now available:

Full source: https://cdn.kernel.org/pub/linux/kernel/v7.x/linux-7.2.10.tar.xz
Patch: https://cdn.kernel.org/pub/linux/kernel/v7.x/patch-7.2.10.xz
PGP Signature: https://cdn.kernel.org/pub/linux/kernel/v7.x/linux-7.2.10.tar.sign

You can view the summary of the changes at the following URL:
https://git.kernel.org/stable/ds/v7.2.10/v7.2.9

Linux kernel 6.18.56 released

Linux kernel version 6.18.56 is now available:

Full source: https://cdn.kernel.org/pub/linux/kernel/v6.x/linux-6.18.56.tar.xz
Patch: https://cdn.kernel.org/pub/linux/kernel/v6.x/patch-6.18.56.xz
PGP Signature: https://cdn.kernel.org/pub/linux/kernel/v6.x/linux-6.18.56.tar.sign

You can view the summary of the changes at the following URL:
https://git.kernel.org/stable/ds/v6.18.56/v6.18.55