← Downloads

Linux Kernel 7.2.8

Kernel v7.2.8 x86_64 TAR.XZ September 25, 2026

Linux 7.2.8 is a stable point release in the 7.2 series, released September 25. It includes the fixes for the four networking root exploits disclosed in September.

Download TAR.XZ Project website ↗

Download Mirrors

Mirror Region Download
kernel.org CDN Primary Global Download
kernel.org Edge Global Download
MIT CSAIL US East Download
University of Maryland US West Download

Linux 7.2.8 is the latest point release of the 7.2 series, the current stable series. It was released on kernel.org on September 25, 2026.

This is the branch most rolling distributions ship today, and the one to be on if you want new hardware support without running a release candidate. 7.1 reached end of life with 7.1.13 on September 2, so anyone still on 7.1 should move here.

Why this release matters

Stable and longterm releases carry no new features, only fixes that have already landed in mainline and been backported. It is also at or beyond the first release in its series to carry fixes for all four networking bugs that received public root exploits on September 18: DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. Three of those need unprivileged user namespaces to reach; one, DiagSpill in SCTP, needs nothing at all.

The same month, CISA also added three older kernel CVEs to its actively-exploited catalog. If you have been deferring kernel updates, this is the batch to take.

Who uses the 7.2 series

Arch, Fedora, openSUSE Tumbleweed, and other fast-moving distributions track this series.

Building it

tar xf linux-7.2.8.tar.xz
cd linux-7.2.8
cp /boot/config-$(uname -r) .config
make olddefconfig
make -j$(nproc)
sudo make modules_install install

Most people should not do this. Your distribution ships kernels through its normal update channel, already configured, signed for Secure Boot, and integrated with your bootloader. Distribution kernels also backport fixes without matching upstream version numbers, so our guide on checking whether your kernel is patched against a CVE is the better way to confirm you are covered.

sudo apt update && sudo apt full-upgrade   # Debian and Ubuntu
sudo dnf upgrade --refresh                 # Fedora
sudo pacman -Syu                           # Arch

A kernel update does not take effect until you reboot, and uname -r reports the running kernel rather than the newest installed one.

Verify Your Download

Every tarball on kernel.org is signed. Verify before building:

curl -O https://cdn.kernel.org/pub/linux/kernel/v7.x/linux-7.2.8.tar.sign
unxz linux-7.2.8.tar.xz
gpg --verify linux-7.2.8.tar.sign