Linux 7.3-rc5 remains unusually large
Linux 7.3-rc5 was released on September 27 with another substantial collection of fixes.
Less than one-third of the changes involve drivers, while approximately one-quarter consists of self-tests. The remaining work includes KVM and architecture corrections, scheduler changes, BPF fixes and networking updates. Linus Torvalds described the distribution of changes as unusual, although not necessarily concerning.
Several memory-management fixes carry direct operational importance. One corrects an Arm64 DAMON bug capable of writing beyond a page-table page, potentially causing memory corruption or crashes. Another fixes an mremap()calculation problem that could panic x86-64 systems using huge pages.
Networking fixes cover Bluetooth, NFC and Netfilter, alongside corrections for IPv6 route leaks, VRF packet checksums, UDP socket handling and packet transmission.
The continued size of the release candidates means Linux 7.3 is still receiving meaningful corrections relatively late in its cycle. Administrators should therefore treat its early performance results as provisional and avoid planning production deployments around an expected release date alone.
An experimental project shares NVIDIA GPUs between KVM guests
A new project called virtio-nvgpu is experimenting with near-native NVIDIA GPU access inside Linux KVM virtual machines.
Instead of assigning the entire GPU to one VM through VFIO, the project keeps the card attached to the host and forwards NVIDIA driver operations across a virtio interface. Guests run NVIDIA’s existing user-space libraries, including Vulkan and NVENC components.
Testing on an RTX 3060 reportedly placed normal GPU-bound rendering within approximately 2% of bare-metal performance. The developers also demonstrated four guests rendering and encoding video simultaneously on one card.
The important limitation is isolation. Guests currently interact with the host NVIDIA driver without a separate IOMMU boundary. Some operations remain unfiltered, and the planned per-guest sandbox has not been implemented. The developers explicitly recommend VFIO or established vGPU technology when tenants do not trust one another.
This makes virtio-nvgpu technically interesting but unsuitable for production multi-tenant infrastructure today. Its larger significance is architectural: it suggests that inexpensive NVIDIA cards could eventually support efficient VM sharing without dedicating an entire GPU to every guest or requiring enterprise vGPU licensing.
Critical NetScaler zero-days are being actively exploited
CISA added two critical Citrix NetScaler ADC and Gateway vulnerabilities—CVE-2026-88771 and CVE-2026-88772—to its Known Exploited Vulnerabilities catalogue on September 27.
These appliances commonly sit at the edge of enterprise networks, providing VPN, authentication and application-delivery services. Successful compromise therefore gives attackers a valuable position before they encounter most internal security controls.
Administrators running affected NetScaler appliances should treat the vendor’s mitigations and updates as emergency work. Internet-facing management interfaces should also be reviewed, logs preserved and appliances examined for indicators of compromise rather than assuming that installing a patch removes an attacker who may already have gained access.
The lesson extends beyond Citrix: perimeter appliances are effectively security infrastructure and servers at the same time. They require asset ownership, rapid patching and compromise assessment—not merely occasional firmware maintenance.
That’s it. If you found this useful, please leave a like, subscribe if you haven’t already, and share it with someone who might enjoy it too.
Until next time, keep exploring.

