Skip to main content

TECH VEDA

Embedded Linux on Edge-AI 23rd Sept 2026 enrollingLinux kernel & Device drivers starts on 24th Oct 2026 enrollingCorporate on-site training - Submit proposal Pick your modulessignup for free monthly live Masterclass Register
News

Kernel & Embedded News: Fragnesia Flaw; AF_ALG Deprecation

This week's TECH VEDA Kernel & Embedded Linux Digest — 5 developments worth your attention, spanning embedded RISC-V hardware, new kernel features, the Yocto build system, and the latest security news.

Kernel & Embedded News: Fragnesia Flaw; AF_ALG Deprecation

This week’s digest covers five developments: the Zhihe A210, an octa-core RVA23 RISC-V SoM with a 12 TOPS NPU and a Buildroot/Debian SDK; Linux 7.2’s busy storage cycle, including dm-inlinecrypt, IO_uring zero-copy receive, and NVMe P2PDMA for multipath devices; the Yocto 5.0.8 Scarthgap LTS point release with CVE backports; the deprecation of the AF_ALG crypto API in Linux 7.2 over its attack surface; and the Fragnesia flaw (CVE-2026-46300) in the XFRM ESP-in-TCP subsystem, which allows local privilege escalation to root.

Welcome to this week’s TECH VEDA Kernel & Embedded Linux Digest — 5 developments worth your attention, spanning embedded RISC-V hardware, new kernel features, the Yocto build system, and the latest security news.

Zhihe A210 RISC-V SoM debuts

Sipeed’s Zhihe A210 is an octa-core RISC-V SoC built around C920 cores and compliant with the latest RVA23 profile. It pairs a 12 TOPS INT8 NPU with LPDDR5/5X memory and ships on a SODIMM-style system-on-module with a carrier board, backed by a Linux SDK offering both Buildroot and Debian images — a strong signal that production-grade RISC-V edge AI hardware is here.

Source: CNX Software


Linux 7.2 storage gains dm-inlinecrypt

The Linux 7.2 merge window brings a busy storage cycle. Device Mapper gains dm-inlinecrypt for inline block-device encryption, IO_uring picks up zero-copy receive notifications and reliability fixes, and NVMe adds per-controller timeout attributes and P2PDMA for multipath devices — meaningful gains for embedded and edge storage workloads.

Source: Phoronix


Yocto 5.0.8 Scarthgap LTS lands

The Yocto Project shipped 5.0.8, another point release on the long-term-support Scarthgap branch. It rolls up security fixes and recipe updates across poky, oe-core and bitbake, including CVE backports for the linux-yocto 6.6 kernel — exactly the kind of maintenance release product teams should track to keep BSPs current.

Source: Yocto Project


Linux 7.2 deprecates AF_ALG crypto API

Kernel developers are deprecating AF_ALG, the user-space interface to the kernel crypto engine, in Linux 7.2, citing its “massive attack surface.” Offloading paths are being dropped first. Embedded projects that route crypto through AF_ALG should plan to migrate to in-kernel or library-based alternatives.

Source: Phoronix


Fragnesia flaw roots Linux via XFRM

Tracked as CVE-2026-46300 and dubbed “Fragnesia,” this flaw lives in the kernel’s XFRM ESP-in-TCP subsystem and lets an unprivileged local user overwrite sensitive system files to escalate to root. If your fleet enables IPsec ESP-in-TCP, prioritise patching to a fixed kernel.

Source: SecurityWeek


The bottom line

The convergence of RISC-V silicon, Yocto-based BSPs, and a fast-moving mainline kernel keeps Embedded Linux at the centre of edge AI and IoT. TECH VEDA distils the ecosystem so you can stay current without combing through a dozen mailing lists and changelogs. See you in the next issue.

Was this worth your time?
RB
Raghu Bharadwaj

Founder, TECH VEDA — 20+ years teaching the Linux kernel, device drivers and embedded systems.

Follow on LinkedIn

Get new posts by email

Kernel, embedded Linux and AI-era engineering — a few sharp reads a month. No spam.

We email occasionally and never share your address.