Linux 7.1.3 Stable Released: ksmbd and KVM SEV Security Fixes, MIPS Reboot Hang Resolved
Greg Kroah-Hartman signed off Linux 7.1.3 on Saturday, July 4, 2026, just twenty-one days after the 7.1 feature release shipped. Alongside it came a full round of longterm kernel updates: 6.18.38, 6.12.95, 6.6.144, and 6.1.177, all released the same day. This is a routine stable patch release rather than a feature drop, but the security fixes inside it are worth acting on promptly if you run any of the affected subsystems.
Security and Memory Safety Fixes
The headline fixes address three separate memory-safety bugs. ksmbd, the in-kernel SMB3 server, had an out-of-bounds heap read that could be triggered by a malformed request from a connected client. KVM’s AMD SEV (Secure Encrypted Virtualization) code had a page-handling overflow that affected hosts running SEV-protected guests. Hyper-V’s nested virtualization path was also missing a bounds check that has now been added.
None of these three carry a published CVE with a high severity score at time of writing, but all three are the kind of bug that gets exploited quietly before public attention catches up, particularly the ksmbd issue on any host that exposes SMB shares to a network with untrusted clients.
# Check whether ksmbd is loaded and in use
lsmod | grep ksmbd
systemctl status ksmbd.service 2>/dev/null
If you are not using ksmbd, this particular fix is moot for your system, but the KVM SEV fix matters for anyone running confidential-computing style virtualization on AMD EPYC hardware, and the Hyper-V fix matters for nested virtualization setups, common in CI runners and cloud-in-cloud lab environments.
NFS Server Subsystem Cleanup
Roughly a dozen commits in this release target the NFS server, clearing up ACL leaks and state management races. These are the kind of bugs that surface as intermittent permission errors or client-visible file locking oddities under load, rather than crashes, which makes them easy to misdiagnose as application bugs rather than kernel issues. Anyone running an NFS server that has seen sporadic, hard-to-reproduce ACL or locking weirdness should treat this release as a candidate fix.
MIPS PREEMPT_RT Reboot Hang Fixed
A more specialized fix resolves a MIPS PREEMPT_RT reboot hang that had been stalling OpenWrt-based router upgrades. This affects a narrower audience, mainly embedded router and networking-appliance builds running the real-time preemption kernel configuration on MIPS hardware, but for that audience it was a hard blocker on installing any update at all until now.
How to Get It
# Debian/Ubuntu: check current kernel, then update through normal channels
uname -r
sudo apt update && sudo apt full-upgrade
# Arch and other rolling releases typically pick this up within days
sudo pacman -Syu
The tarball and signed ChangeLog-7.1.3 are available directly from kernel.org for anyone who wants to verify Greg Kroah-Hartman’s PGP signature before building from source. Distribution kernel teams for Debian, Ubuntu, Fedora, and other point-release distros generally backport the security-relevant subset of stable patches within days rather than waiting for a scheduled kernel bump, so checking your distribution’s changelog is worthwhile even if you are not tracking upstream stable releases directly.
What’s Next
The 7.2 development cycle is already in its rc phase, with rc1 tagged June 28 and a final release expected in the second half of August. Expect at least one more 7.1.x stable point release before 7.2 ships, following the kernel’s usual overlap between a maintained stable branch and the next cycle’s release candidates.