A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-lowlatency: Linux low latency kernel - linux-nvidia: Linux kernel for NVIDIA systems - linux-nvidia-lowlatency: Linux low latency kernel for NVIDIA systems - linux-hwe-6.8: Linux hardware enablement (HWE) kernel - linux-ibm-6.8: Linux kernel for IBM cloud systems - linux-lowlatency-hwe-6.8: Linux low latency kernel Details: Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is ...
Read the Full AdvisoryThe problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1026-gkeop 6.8.0-1026.29 linux-image-6.8.0-1040-ibm 6.8.0-1040.40 linux-image-6.8.0-1042-aws 6.8.0-1042.44 linux-image-6.8.0-1042-aws-64k 6.8.0-1042.44 linux-image-6.8.0-1042-nvidia 6.8.0-1042.45+1 linux-image-6.8.0-1042-nvidia-64k 6.8.0-1042.45+1 linux-image-6.8.0-1042-nvidia-lowlatency 6.8.0-1042.45.1 linux-image-6.8.0-1042-nvidia-lowlatency-64k 6.8.0-1042.45.1 linux-image-6.8.0-87-generic 6.8.0-87.88 linux-image-6.8.0-87-generic-64k 6.8.0-87.88 linux-image-6.8.0-87-lowlatency 6.8.0-87.88.1 linux-image-6.8.0-87-lowlatency-64k 6.8.0-87.88.1 linux-image-aws-6.8 6.8.0-1042.44 linux-image-aws-64k-6.8 6.8.0-1042.44 linux-image-aws-64k-lts-24.04 6.8.0-1042.44 linux-image-aws-lts-24.04 6.8.0-1042.44 linux-image-generic 6.8.0-87.88 linux-image-generic-6.8 6.8.0-87.88 linux-image-generic-64k 6.8.0-87.88 linux-image-generic-64k-6.8 6.8.0-87.88 linux-image-generic-lpae 6.8.0-87.88 linux-image-gkeop 6.8.0-1026.29 linux-image-gkeop-6.8 6.8.0-1026.29 linux-image-ibm 6.8.0-1040.40 linux-image-ibm-6.8 6.8.0-1040.40 linux-image-ibm-classic 6.8.0-1040.40 linux-image-ibm-lts-24.04 6.8.0-1040.40 linux-image-kvm 6.8.0-87.88 linux-image-lowlatency 6.8.0-87.88.1 linux-image-lowlatency-6.8 6.8.0-87.88.1 linux-image-lowlatency-64k 6.8.0-87.88.1 linux-image-lowlatency-64k-6.8 6.8.0-87.88.1 linux-image-nvidia 6.8.0-1042.45 linux-image-nvidia-6.8 6.8.0-1042.45 linux-image-nvidia-64k 6.8.0-1042.45 linux-image-nvidia-64k-6.8 6.8.0-1042.45 linux-image-nvidia-lowlatency 6.8.0-1042.45.1 linux-image-nvidia-lowlatency-6.8 6.8.0-1042.45.1 linux-image-nvidia-lowlatency-64k 6.8.0-1042.45.1 linux-image-nvidia-lowlatency-64k-6.8 6.8.0-1042.45.1 linux-image-virtual 6.8.0-87.88 linux-image-virtual-6.8 6.8.0-87.88 Ubuntu 22.04 LTS linux-image-6.8.0-1040-ibm 6.8.0-1040.40~22.04.1 linux-image-6.8.0-87-generic 6.8.0-87.88~22.04.1 linux-image-6.8.0-87-lowlatency 6.8.0-87.88.1~22.04.1 linux-image-6.8.0-87-lowlatency-64k 6.8.0-87.88.1~22.04.1 linux-image-generic-6.8 6.8.0-87.88~22.04.1 linux-image-generic-64k-6.8 6.8.0-87.88~22.04.1 linux-image-generic-64k-hwe-22.04 6.8.0-87.88~22.04.1 linux-image-generic-hwe-22.04 6.8.0-87.88~22.04.1 linux-image-ibm-6.8 6.8.0-1040.40~22.04.1 linux-image-lowlatency-6.8 6.8.0-87.88.1~22.04.1 linux-image-lowlatency-64k-6.8 6.8.0-87.88.1~22.04.1 linux-image-lowlatency-64k-hwe-22.04 6.8.0-87.88.1~22.04.1 linux-image-lowlatency-hwe-22.04 6.8.0-87.88.1~22.04.1 linux-image-oem-22.04 6.8.0-87.88~22.04.1 linux-image-oem-22.04a 6.8.0-87.88~22.04.1 linux-image-oem-22.04b 6.8.0-87.88~22.04.1 linux-image-oem-22.04c 6.8.0-87.88~22.04.1 linux-image-oem-22.04d 6.8.0-87.88~22.04.1 linux-image-virtual-6.8 6.8.0-87.88~22.04.1 linux-image-virtual-hwe-22.04 6.8.0-87.88~22.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.
https://ubuntu.com/security/notices/USN-7861-1
CVE-2025-37838, CVE-2025-38118, CVE-2025-38352, CVE-2025-40300
https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1040.40 https://launchpad.net/ubuntu/+source/linux-hwe-6.8/6.8.0-87.88~22.04.1 https://launchpad.net/ubuntu/+source/linux-ibm-6.8/6.8.0-1040.40~22.04.1
Get the latest Linux and open source security news straight to your inbox.