The Linux 7.2 merge window has introduced several security-focused changes, including support for updating Intel Trusted Domain Extensions (TDX) modules on running systems, a step aimed at improving maintainability for confidential-computing deployments without requiring downtime. The kernel also adds arm64 hardening to remove data regions from the linear map, strengthens openat2() with OPENAT2_REGULAR and EFTYPE handling, and extends fs-verity support in iomap alongside a new dm-inlinecrypt device-mapper target.
Additional protections target exploit resistance and attack-surface reduction across the kernel. The slab allocator now supports Clang allocation tokens to make cross-object memory corruption harder to exploit, while PowerPC’s hardware-optimized MD5 implementation is being removed and AF_ALG is being deprecated after multiple recent security issues, including removal of its hardware-accelerator support. The update also includes broader networking and BPF changes, but the most notable theme is a sustained push to harden core kernel subsystems and reduce exposure from legacy or problematic components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The Linux 7.2 merge window began with the release of Linux 7.1. This marked the start of merging changes later summarized as part of the 7.2 development cycle.
During the 7.2 merge window, the kernel gained security-relevant changes including live replacement support for Intel TDX modules, openat2() hardening via OPENAT2_REGULAR and EFTYPE, slab allocator support for Clang allocation tokens, AF_ALG deprecation and hardware-accelerator removal, PowerPC MD5 implementation removal, and fs-verity support in iomap. The arm64 linear-map hardening work was also merged and then temporarily reverted because of a KVM regression.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.