The 7.0.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree. It also contains a fix for the dirtyfrag vulnerability. This covers CVE-2026-43284 and CVE-2026-43500. For users who experience a problem with the 7.0.4 rebase, a build of 6.19.14 with just the dirtyfrag fixes should be available in koji shortly.
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2026-8cffa03dad
Please log in to add feedback.
| 0 | 7 | Test Case kernel regression |
This update has been submitted for testing by jforbes.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'waiting'.
Tested on LOTs of arm devices including: RPi5B, RPi4 (multiple variants), RPi3, Jetson Orin AGX, Jetson TX1/TX2, Rock5B, Rock3C, Rock960, imx93frdm, rock64, Jetson Nano, Pine64, Pine64-LTS, RPi zeo2w, BeableBone-AI64, Macbin, Lenoxo x13s, probably some others I missed.
This kernel doesn't have new kernel headers?
Boots OK on my test system, confirmed GitHub dirtyfrag exploit no longer works.
@pawef9 kernel-headers is a separate source package, I assume @jforbes will update it soon on a slightly less rushed schedule, we are trying to get the dirtyfrag fix out ASAP.
Seems this also includes this patch? https://cdn.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.5
Yes, headers is not required to build new modules or such, it is simply for userspace. There is no reason a 7.0.x kernel requires 7.0.x headers. I plan to update headers with the next regular build. And yes, it does include the patch from 7.0.5, but these builds were started before that was released which is why the versioning.
No issues noted. Running great on Lenovo Yoga (AMD).
7.0.5 is already out, maybe we skip this one?
@ksenchy no. We are trying to get the update out ASAP. it would be pointless to set the whole process back a couple of hours by waiting for a 7.0.5 build.
This update's test gating status has been changed to 'passed'.
This update has been submitted for stable by adamwill.
@adamwill fair enough
@ksenchy 7.0.5 upstream only fixes copyfail2, not dirtyfrag. This build has the dirtyfrag patch added in by Fedora's kernel SIG.
@lordalfredo yes, 7.0.5 only has one commit vs 7.0.4. They pushed it due security concerns. But seems like we want to push this one out ASAP also due security concerns. Fair enough
Our 7.0.4 already carries the commit that 7.0.5 shipped. We will not do a 7.0.5 because that patch is in this kernel. It fixes both CVEs.
Ok on ThinkPad P14s AMD RyzenAI Pro 9 HX 370; fiwa-20260409, fc44/xfce/x11
Works for me on a number of systems of various x86_64 generations and a few aarch64 systems.
This update has been pushed to stable.
Works for me, the default tests passed OK..
Work Station, Asus prime mobo - Ryzen5 5600g/iGPU, 400 Series Chipset, 32 GiB RAM. (UEFI) Secure boot, 2x SSD's > RAID (ext4)
Ryzen 5800X3D + RX 7900XTX + ConnectX-4 Lx Compared dmesg, no unexpected changes from last kernel. KDE desktop works fine. No surprises mounting and using btrfs, cifs, ntfs-3g, and exfat via iSER. Started two Steam games, no problems seen or heard. LGTM
All is good
Works
Thinkpad T14 AMD Ryzen 5 Pro
PASS
stable in games rx 7900 xtx + 9800x3d
Working fine on Thinkpad T430
Works.
Since this update, chromium and ymex-ng do not launch anymore.
yumex Failed to register: Le délai d’attente est dépassé
chromium-browser nvc0_screen_create:805 - Base screen init failed: -19 nvc0_screen_create:805 - Base screen init failed: -19 ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-tabrmd.so.0 ERROR:tcti:src/tss2-tcti/tcti-device.c:455:Tss2_Tcti_Device_Init() Failed to open specified TCTI device file /dev/tpmrm0: Permission non accordée ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-device.so.0 ERROR:tcti:src/tss2-tcti/tcti-device.c:455:Tss2_Tcti_Device_Init() Failed to open specified TCTI device file /dev/tpm0: Permission non accordée ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-device.so.0 ERROR:tcti:src/tss2-tcti/tcti-device.c:455:Tss2_Tcti_Device_Init() Failed to open specified TCTI device file /dev/tcm0: Aucun fichier ou dossier de ce nom ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-device.so.0 WARNING:tcti:src/util-io/io.c:262:socket_connect() Failed to connect to host 127.0.0.1, port 2321: errno 111: Connexion refusée ERROR:tcti:src/tss2-tcti/tcti-swtpm.c:617:Tss2_Tcti_Swtpm_Init() Cannot connect to swtpm TPM socket ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-swtpm.so.0 WARNING:tcti:src/util-io/io.c:262:socket_connect() Failed to connect to host 127.0.0.1, port 2321: errno 111: Connexion refusée ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-mssim.so.0 ERROR:tcti:src/tss2-tcti/tctildr-dl.c:263:tctildr_get_default() No standard TCTI could be loaded ERROR:tcti:src/tss2-tcti/tctildr.c:477:tctildr_init_context_data() Failed to instantiate TCTI ERROR:fapi:src/tss2-fapi/api/Fapi_Initialize.c:233:Fapi_Initialize_Finish() Initializing TCTI. ErrorCode (0x000a000a) WARNING: Listing FAPI token objects failed: "tcti:IO failure" Please see https://github.com/tpm2-software/tpm2-pkcs11/blob/1.9.1/docs/FAPI.md for more details WARNING: FAPI backend was not initialized. ERROR: Unhandled search index: 2 ERROR: Could not find or create a pkcs11 store ERROR: Consider exporting TPM2_PKCS11_STORE to point to a valid store directory WARNING: ESYSDB backend was not initialized. ERROR: Neither FAPI nor ESYSDB backends could be initialized. [12833:12863:0509/133144.940049:ERROR:google_apis/gcm/engine/registration_request.cc:291] Registration response error message: DEPRECATED_ENDPOINT [12833:12930:0509/133207.238595:ERROR:content/browser/browser_main_loop.cc:274] GLib: g_main_context_pop_thread_default: assertion 'stack != NULL' failed [12833:12931:0509/133207.238605:ERROR:content/browser/browser_main_loop.cc:274] GLib: g_main_context_pop_thread_default: assertion 'stack != NULL' failed [12833:12929:0509/133207.238615:ERROR:content/browser/browser_main_loop.cc:274] GLib: g_main_context_pop_thread_default: assertion 'stack != NULL' failed [12833:12863:0509/133208.932028:ERROR:google_apis/gcm/engine/registration_request.cc:291] Registration response error message: DEPRECATED_ENDPOINT [0509/133217.777121:ERROR:third_party/crashpad/crashpad/util/file/file_io_posix.cc:145] open /proc/13097/auxv: Permission denied (13) [0509/133217.777289:ERROR:third_party/crashpad/crashpad/util/linux/ptracer.cc:454] ptrace: No such process (3) [0509/133217.777313:ERROR:third_party/crashpad/crashpad/util/linux/ptracer.cc:480] Unexpected registers size 0 != 216 [0509/133217.777331:WARNING:third_party/crashpad/crashpad/snapshot/linux/process_reader_linux.cc:400] Couldn't initialize main thread. [0509/133217.783422:ERROR:third_party/crashpad/crashpad/util/linux/scoped_ptrace_attach.cc:37] process not stopped [0509/133217.783482:ERROR:third_party/crashpad/crashpad/util/linux/ptracer.cc:567] ptrace: No such process (3) [0509/133217.783492:ERROR:third_party/crashpad/crashpad/snapshot/linux/process_snapshot_linux.cc:78] Couldn't read exception info [0509/133217.783529:ERROR:third_party/crashpad/crashpad/util/linux/scoped_ptrace_attach.cc:45] ptrace: No such process (3)
It's crashing! I am getting the following error message on my x86_64 machine and apps are not running.
BUG: kernel NULL pointer dereference, address: 0000000000000000 [nouveau]
Works well. No issues. Fedora, Brave, and Chrome browsers work OK. Xonotic gaming works. BTRFS full balance/no filters OK.
Ryzen 7800x3d, Asus TUF B650E-E, Nvidia from rpmfusion working with amd/gpu enabled in bios.
Enoch AI (Mistral) working well.
Lenovo P16s Gen2 AMD (7840U + 780M) : everything is working fine. Tests run and uploaded.
Kernel 7.0.4 + driver "nvidia-580xx", it is ok. kernel 7.0.4 + driver "nouveau", not ok. kernel 6.9.14 + driver "nouveau", it is ok