Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8374-1 June 02, 2026 linux-aws-6.17, linux-gcp, linux-gcp-6.17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-aws-6.17: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp-6.17: Linux kernel for Google Cloud Platform (GCP) systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500, CVE-2026-45998, CVE-2026-46000) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503, CVE-2026-46300) Qualys discovered that a race condition existed in the ptrace subsystem of the Linux kernel when privileged processes are exiting. An unprivileged local attacker could use this issue to expose sensitive information. (CVE-2026-46333) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contain a memory leak when handlingAppArmor notifications. A local attacker could use this to cause resource exhaustion. (CVE-2026-47326) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contain a NULL pointer dereference when handling AppArmor notifications. A local attacker could use this to cause a kernel oops. (CVE-2026-47327) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained an invalid free when handling AppArmor notifications. A local attacker could use this to corrupt kernel memory. (CVE-2026-47328) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained insufficient validation of AppArmor notification responses. A local attacker could use this to allow crafted responses to be processed. (CVE-2026-47329) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 used an uninitialized variable when handling AppArmor notifications. A local attacker could use this to cause incorrect caching of data. (CVE-2026-47330) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained an out-of-bounds (OOB) read when handling AppArmor notifications. A local attacker could use this to cause information disclosure of kernel memory. (CVE-2026-47332) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a out-of-bounds (OOB) read when handling AppArmor notifications. A local attacker could use this to cause kernel memory corruption and, theoretically, influence processing of AppArmor policies. (CVE-2026-47333) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained incorrect holding of locks when handling AppArmor notifications. A local attacker could use this to cause a kernel panic or deadlock. (CVE-2026-47334) Tristan Madani and Trevor Lawrence have each independently discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a NULL pointer dereference when handling AppArmor network socket mediation. A local attacker could use this to cause a kernel oops. (CVE-2026-47337) Several securityissues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - S390 architecture; - Cryptographic API; - GPU drivers; - Ethernet bonding driver; - Network file system (NFS) server daemon; - Distributed Switch Architecture; - Netfilter; - Control group (cgroup); - Kernel kexec() syscall; - Memory management; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - RDS protocol; - RxRPC session sockets; - TLS protocol; - Unix domain sockets; - AppArmor security module; (CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-31676, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-43494, CVE-2026-45966, CVE-2026-46028) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 linux-image-6.17.0-1018-gcp 6.17.0-1018.19 linux-image-6.17.0-1018-gcp-64k 6.17.0-1018.19 linux-image-gcp 6.17.0-1018.19 linux-image-gcp-6.17 6.17.0-1018.19 linux-image-gcp-64k 6.17.0-1018.19 linux-image-gcp-64k-6.17 6.17.0-1018.19 Ubuntu 24.04 LTS linux-image-6.17.0-1017-aws 6.17.0-1017.17~24.04.1 linux-image-6.17.0-1017-aws-64k 6.17.0-1017.17~24.04.1 linux-image-6.17.0-1018-gcp 6.17.0-1018.19~24.04.1 linux-image-6.17.0-1018-gcp-64k 6.17.0-1018.19~24.04.1 linux-image-aws 6.17.0-1017.17~24.04.1 linux-image-aws-6.17 6.17.0-1017.17~24.04.1 linux-image-aws-64k 6.17.0-1017.17~24.04.1 linux-image-aws-64k-6.17 6.17.0-1017.17~24.04.1 linux-image-gcp 6.17.0-1018.19~24.04.1 linux-image-gcp-6.17 6.17.0-1018.19~24.04.1 linux-image-gcp-64k 6.17.0-1018.19~24.04.1 linux-image-gcp-64k-6.17 6.17.0-1018.19~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8374-1 CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-31676, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-43284, CVE-2026-43494, CVE-2026-43500, CVE-2026-43503, CVE-2026-45966, CVE-2026-45998, CVE-2026-46000, CVE-2026-46028, CVE-2026-46300, CVE-2026-46333, CVE-2026-47326, CVE-2026-47327, CVE-2026-47328, CVE-2026-47329, CVE-2026-47330, CVE-2026-47332, CVE-2026-47333, CVE-2026-47334, CVE-2026-47337 Package Information: https://launchpad.net/ubuntu/+source/linux-gcp/6.17.0-1018.19 https://launchpad.net/ubuntu/+source/linux-aws-6.17/6.17.0-1017.17~24.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-6.17/6.17.0-1018.19~24.04.1 . Multiple critical issues fixed in the Ubuntu Linux kernel elevate security risks. Essential updates are highly recommended.. Linux kernel security, Ubuntu kernel updates, privilege escalation, AppArmor issues. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8351-1 June 01, 2026 linux-lowlatency vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-lowlatency: Linux low latency kernel Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Ethernet bonding driver; - Packet sockets; - TLS protocol; (CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-179-lowlatency 5.15.0-179.189 linux-image-5.15.0-179-lowlatency-64k 5.15.0-179.189 linux-image-lowlatency 5.15.0.179.151 linux-image-lowlatency-5.15 5.15.0.179.151 linux-image-lowlatency-64k 5.15.0.179.151 linux-image-lowlatency-64k-5.15 5.15.0.179.151 linux-image-lowlatency-64k-hwe-20.04 5.15.0.179.151 linux-image-lowlatency-hwe-20.04 5.15.0.179.151 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manuallyuninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8351-1 CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028 Package Information: https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-179.189 . Several security issues fixed in Ubuntu's Low Latency Linux kernel, including privilege escalation flaws. Update now!. Ubuntu Security, Linux Kernel, Low Latency, Privilege Escalation, Security Issues. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8289-2 May 25, 2026 linux-nvidia-6.8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-nvidia-6.8: Linux kernel for NVIDIA systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Cryptographic API; - Compute Acceleration Framework; - Drivers core; - Null block device driver; - Ublk userspace block driver; - Bluetooth drivers; - Counter interface drivers; - DMA engine subsystem; - DPLL subsystem; - GPU drivers; - HID subsystem; - Intel Trace Hub HW tracing drivers; - IIO ADC drivers; - IIO subsystem; - On-Chip Interconnect management framework; - IRQ chip drivers; - Modular ISDN driver; - LED subsystem; - Multiple devices driver; - UACCE accelerator framework; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - NVME drivers; - PHY drivers; - x86 platform drivers; - i.MX PM domains; - SCSI subsystem; - SLIMbus drivers; - SPI subsystem; - TCM subsystem; - W1 Dallas's 1-wire bus driver; - Xen hypervisor drivers; - BTRFS file system; - EFI Variable file system; - exFAT file system; - Ext4 file system; - HFS+ file system; - Networkfile system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - SMB network file system; - Scheduler infrastructure; - Netfilter; - NFC subsystem; - Tracing infrastructure; - io_uring subsystem; - BPF subsystem; - Perf events; - Floating proportions library; - Memory management; - Bluetooth subsystem; - CAN network layer; - Ceph Core library; - Networking core; - IPv4 networking; - IPv6 networking; - L2TP protocol; - MAC80211 subsystem; - NET/ROM layer; - Packet sockets; - Network traffic control; - SCTP protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - ALSA AC97 driver; - Generic PCM loopback sound driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - Texas InstrumentS Audio (ASoC/HDA) drivers; - USB sound devices; - KVM subsystem; (CVE-2024-50004, CVE-2024-58096, CVE-2024-58097, CVE-2025-37926, CVE-2025-38201, CVE-2025-38591, CVE-2025-40039, CVE-2025-40082, CVE-2025-40149, CVE-2025-68351, CVE-2025-68358, CVE-2025-68365, CVE-2025-68725, CVE-2025-68749, CVE-2025-68803, CVE-2025-68823, CVE-2025-71160, CVE-2025-71162, CVE-2025-71163, CVE-2025-71180, CVE-2025-71182, CVE-2025-71183, CVE-2025-71184, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71192, CVE-2025-71193, CVE-2025-71194, CVE-2025-71195, CVE-2025-71196, CVE-2025-71197, CVE-2025-71198, CVE-2025-71199, CVE-2025-71200, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2025-71225, CVE-2025-71268, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22994, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23000, CVE-2026-23001, CVE-2026-23003, CVE-2026-23005, CVE-2026-23006, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23020,CVE-2026-23021, CVE-2026-23025, CVE-2026-23026, CVE-2026-23030, CVE-2026-23031, CVE-2026-23032, CVE-2026-23033, CVE-2026-23035, CVE-2026-23037, CVE-2026-23038, CVE-2026-23047, CVE-2026-23049, CVE-2026-23050, CVE-2026-23053, CVE-2026-23054, CVE-2026-23056, CVE-2026-23057, CVE-2026-23058, CVE-2026-23059, CVE-2026-23061, CVE-2026-23062, CVE-2026-23063, CVE-2026-23064, CVE-2026-23065, CVE-2026-23068, CVE-2026-23069, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23086, CVE-2026-23087, CVE-2026-23088, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23094, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23102, CVE-2026-23103, CVE-2026-23105, CVE-2026-23107, CVE-2026-23108, CVE-2026-23110, CVE-2026-23113, CVE-2026-23116, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23123, CVE-2026-23124, CVE-2026-23125, CVE-2026-23126, CVE-2026-23128, CVE-2026-23129, CVE-2026-23131, CVE-2026-23133, CVE-2026-23135, CVE-2026-23136, CVE-2026-23139, CVE-2026-23140, CVE-2026-23141, CVE-2026-23142, CVE-2026-23144, CVE-2026-23145, CVE-2026-23146, CVE-2026-23148, CVE-2026-23150, CVE-2026-23151, CVE-2026-23156, CVE-2026-23159, CVE-2026-23160, CVE-2026-23163, CVE-2026-23164, CVE-2026-23166, CVE-2026-23167, CVE-2026-23168, CVE-2026-23170, CVE-2026-23172, CVE-2026-23173, CVE-2026-23176, CVE-2026-23178, CVE-2026-23179, CVE-2026-23180, CVE-2026-23182, CVE-2026-23187, CVE-2026-23190, CVE-2026-23191, CVE-2026-23193, CVE-2026-23198, CVE-2026-23200, CVE-2026-23204, CVE-2026-23205, CVE-2026-23206, CVE-2026-23212, CVE-2026-23213, CVE-2026-23214, CVE-2026-23215, CVE-2026-23216, CVE-2026-23254, CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23260, CVE-2026-23261, CVE-2026-23262, CVE-2026-23264, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078) Updateinstructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-6.8.0-1054-nvidia 6.8.0-1054.57~22.04.1 linux-image-6.8.0-1054-nvidia-64k 6.8.0-1054.57~22.04.1 linux-image-nvidia-6.8 6.8.0-1054.57~22.04.1 linux-image-nvidia-64k-6.8 6.8.0-1054.57~22.04.1 linux-image-nvidia-64k-hwe-22.04 6.8.0-1054.57~22.04.1 linux-image-nvidia-hwe-22.04 6.8.0-1054.57~22.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8289-2 https://ubuntu.com/security/notices/USN-8289-1 CVE-2024-50004, CVE-2024-58096, CVE-2024-58097, CVE-2025-37926, CVE-2025-38201, CVE-2025-38591, CVE-2025-40039, CVE-2025-40082, CVE-2025-40149, CVE-2025-68351, CVE-2025-68358, CVE-2025-68365, CVE-2025-68725, CVE-2025-68749, CVE-2025-68803, CVE-2025-68823, CVE-2025-71160, CVE-2025-71162, CVE-2025-71163, CVE-2025-71180, CVE-2025-71182, CVE-2025-71183, CVE-2025-71184, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71192, CVE-2025-71193, CVE-2025-71194, CVE-2025-71195, CVE-2025-71196, CVE-2025-71197, CVE-2025-71198, CVE-2025-71199, CVE-2025-71200, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2025-71225, CVE-2025-71268, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22994, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23000, CVE-2026-23001, CVE-2026-23003, CVE-2026-23005, CVE-2026-23006, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23020, CVE-2026-23021, CVE-2026-23025, CVE-2026-23026, CVE-2026-23030, CVE-2026-23031, CVE-2026-23032, CVE-2026-23033, CVE-2026-23035, CVE-2026-23037, CVE-2026-23038, CVE-2026-23047, CVE-2026-23049, CVE-2026-23050, CVE-2026-23053, CVE-2026-23054, CVE-2026-23056, CVE-2026-23057, CVE-2026-23058, CVE-2026-23059, CVE-2026-23061, CVE-2026-23062, CVE-2026-23063, CVE-2026-23064, CVE-2026-23065, CVE-2026-23068, CVE-2026-23069, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23086, CVE-2026-23087, CVE-2026-23088, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23094, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23102, CVE-2026-23103, CVE-2026-23105, CVE-2026-23107, CVE-2026-23108, CVE-2026-23110, CVE-2026-23113, CVE-2026-23116, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23123, CVE-2026-23124, CVE-2026-23125, CVE-2026-23126, CVE-2026-23128, CVE-2026-23129, CVE-2026-23131, CVE-2026-23133, CVE-2026-23135, CVE-2026-23136, CVE-2026-23139, CVE-2026-23140, CVE-2026-23141, CVE-2026-23142, CVE-2026-23144, CVE-2026-23145, CVE-2026-23146, CVE-2026-23148, CVE-2026-23150, CVE-2026-23151, CVE-2026-23156, CVE-2026-23159, CVE-2026-23160, CVE-2026-23163, CVE-2026-23164, CVE-2026-23166, CVE-2026-23167, CVE-2026-23168, CVE-2026-23170, CVE-2026-23172, CVE-2026-23173, CVE-2026-23176, CVE-2026-23178, CVE-2026-23179, CVE-2026-23180, CVE-2026-23182, CVE-2026-23187, CVE-2026-23190, CVE-2026-23191, CVE-2026-23193, CVE-2026-23198, CVE-2026-23200, CVE-2026-23204, CVE-2026-23205, CVE-2026-23206, CVE-2026-23212, CVE-2026-23213, CVE-2026-23214, CVE-2026-23215, CVE-2026-23216, CVE-2026-23254,CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23260, CVE-2026-23261, CVE-2026-23262, CVE-2026-23264, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078 Package Information: https://launchpad.net/ubuntu/+source/linux-nvidia-6.8/6.8.0-1054.57~22.04.1 . Several critical security issues impacting Ubuntu 22.04 LTS Linux kernel for NVIDIA systems resolved with this update. . Linux Security Update, Ubuntu Kernel Patch, NVIDIA Linux Kernel. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8277-2 May 22, 2026 linux-oracle-6.17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oracle-6.17: Linux kernel for Oracle Cloud systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - S390 architecture; - Cryptographic API; - GPU drivers; - Ethernet bonding driver; - Network file system (NFS) server daemon; - Distributed Switch Architecture; - Netfilter; - Control group (cgroup); - Kernel kexec() syscall; - Memory management; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - TLS protocol; - Unix domain sockets; (CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.17.0-1014-oracle 6.17.0-1014.14~24.04.1 linux-image-6.17.0-1014-oracle-64k 6.17.0-1014.14~24.04.1 linux-image-oracle 6.17.0-1014.14~24.04.1 linux-image-oracle-6.17 6.17.0-1014.14~24.04.1 linux-image-oracle-64k 6.17.0-1014.14~24.04.1 linux-image-oracle-64k-6.17 6.17.0-1014.14~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8277-2 https://ubuntu.com/security/notices/USN-8277-1 CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078 Package Information: https://launchpad.net/ubuntu/+source/linux-oracle-6.17/6.17.0-1014.14~24.04.1 . Several security issues were found in Ubuntu's Linux kernel, requiring immediate updates to maintain system integrity and security.. Ubuntu Security Notice, Linux Kernel, Privilege Escalation, Security Updates. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8278-1 May 19, 2026 linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-ibm, linux-ibm-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-raspi, linux-raspi-realtime, linux-realtime, linux-realtime-6.8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-aws-fips: Linux kernel for Amazon Web Services (AWS) systems with FIPS - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-lowlatency: Linux low latency kernel - linux-raspi: Linux kernel for Raspberry Pi systems - linux-raspi-realtime: Linux kernel for Raspberry Pi Real-time systems - linux-realtime: Linux kernel for Real-time systems - linux-ibm-6.8: Linux kernel for IBM cloud systems - linux-lowlatency-hwe-6.8: Linux low latency kernel - linux-realtime-6.8: Linux kernel for Real-time systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64architecture; - x86 architecture; - Cryptographic API; - Compute Acceleration Framework; - Drivers core; - Null block device driver; - Ublk userspace block driver; - Bluetooth drivers; - Counter interface drivers; - DMA engine subsystem; - DPLL subsystem; - GPU drivers; - HID subsystem; - Intel Trace Hub HW tracing drivers; - IIO ADC drivers; - IIO subsystem; - On-Chip Interconnect management framework; - IRQ chip drivers; - Modular ISDN driver; - LED subsystem; - Multiple devices driver; - UACCE accelerator framework; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - NVME drivers; - PHY drivers; - x86 platform drivers; - i.MX PM domains; - SCSI subsystem; - SLIMbus drivers; - SPI subsystem; - TCM subsystem; - W1 Dallas's 1-wire bus driver; - Xen hypervisor drivers; - BTRFS file system; - EFI Variable file system; - exFAT file system; - Ext4 file system; - HFS+ file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - SMB network file system; - Scheduler infrastructure; - Netfilter; - NFC subsystem; - Tracing infrastructure; - io_uring subsystem; - BPF subsystem; - Perf events; - Floating proportions library; - Memory management; - Bluetooth subsystem; - CAN network layer; - Ceph Core library; - Networking core; - IPv4 networking; - IPv6 networking; - L2TP protocol; - MAC80211 subsystem; - NET/ROM layer; - Packet sockets; - Network traffic control; - SCTP protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - ALSA AC97 driver; - Generic PCM loopback sound driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - Texas InstrumentS Audio (ASoC/HDA) drivers; - USB sound devices; - KVM subsystem; (CVE-2024-50004, CVE-2024-58096,CVE-2024-58097, CVE-2025-37926, CVE-2025-38201, CVE-2025-38591, CVE-2025-40039, CVE-2025-40082, CVE-2025-40149, CVE-2025-68351, CVE-2025-68358, CVE-2025-68365, CVE-2025-68725, CVE-2025-68749, CVE-2025-68803, CVE-2025-68823, CVE-2025-71160, CVE-2025-71162, CVE-2025-71163, CVE-2025-71180, CVE-2025-71182, CVE-2025-71183, CVE-2025-71184, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71192, CVE-2025-71193, CVE-2025-71194, CVE-2025-71195, CVE-2025-71196, CVE-2025-71197, CVE-2025-71198, CVE-2025-71199, CVE-2025-71200, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2025-71225, CVE-2025-71268, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22994, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23000, CVE-2026-23001, CVE-2026-23003, CVE-2026-23005, CVE-2026-23006, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23020, CVE-2026-23021, CVE-2026-23025, CVE-2026-23026, CVE-2026-23030, CVE-2026-23031, CVE-2026-23032, CVE-2026-23033, CVE-2026-23035, CVE-2026-23037, CVE-2026-23038, CVE-2026-23047, CVE-2026-23049, CVE-2026-23050, CVE-2026-23053, CVE-2026-23054, CVE-2026-23056, CVE-2026-23057, CVE-2026-23058, CVE-2026-23059, CVE-2026-23061, CVE-2026-23062, CVE-2026-23063, CVE-2026-23064, CVE-2026-23065, CVE-2026-23068, CVE-2026-23069, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23086, CVE-2026-23087, CVE-2026-23088, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23094, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23102, CVE-2026-23103, CVE-2026-23105, CVE-2026-23107, CVE-2026-23108, CVE-2026-23110, CVE-2026-23113, CVE-2026-23116, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23123, CVE-2026-23124, CVE-2026-23125,CVE-2026-23126, CVE-2026-23128, CVE-2026-23129, CVE-2026-23131, CVE-2026-23133, CVE-2026-23135, CVE-2026-23136, CVE-2026-23139, CVE-2026-23140, CVE-2026-23141, CVE-2026-23142, CVE-2026-23144, CVE-2026-23145, CVE-2026-23146, CVE-2026-23148, CVE-2026-23150, CVE-2026-23151, CVE-2026-23156, CVE-2026-23159, CVE-2026-23160, CVE-2026-23163, CVE-2026-23164, CVE-2026-23166, CVE-2026-23167, CVE-2026-23168, CVE-2026-23170, CVE-2026-23172, CVE-2026-23173, CVE-2026-23176, CVE-2026-23178, CVE-2026-23179, CVE-2026-23180, CVE-2026-23182, CVE-2026-23187, CVE-2026-23190, CVE-2026-23191, CVE-2026-23193, CVE-2026-23198, CVE-2026-23200, CVE-2026-23202, CVE-2026-23204, CVE-2026-23205, CVE-2026-23206, CVE-2026-23212, CVE-2026-23213, CVE-2026-23214, CVE-2026-23215, CVE-2026-23216, CVE-2026-23254, CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23260, CVE-2026-23261, CVE-2026-23262, CVE-2026-23264, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1041-gkeop 6.8.0-1041.44 linux-image-6.8.0-1054-gke 6.8.0-1054.60 linux-image-6.8.0-1054-gke-64k 6.8.0-1054.60 linux-image-6.8.0-1055-aws 6.8.0-1055.58 linux-image-6.8.0-1055-aws-64k 6.8.0-1055.58 linux-image-6.8.0-1055-aws-fips 6.8.0-1055.58+fips1 Available with Ubuntu Pro linux-image-6.8.0-1055-ibm 6.8.0-1055.56 linux-image-6.8.0-1056-raspi 6.8.0-1056.60 linux-image-6.8.0-1058-gcp 6.8.0-1058.61 linux-image-6.8.0-1058-gcp-64k 6.8.0-1058.61 linux-image-6.8.0-1058-gcp-fips 6.8.0-1058.61+fips1 Available with Ubuntu Pro linux-image-6.8.0-117-generic 6.8.0-117.117 linux-image-6.8.0-117-generic-64k 6.8.0-117.117 linux-image-6.8.0-117-lowlatency 6.8.0-117.117.1 linux-image-6.8.0-117-lowlatency-64k 6.8.0-117.117.1 linux-image-6.8.0-2045-raspi-realtime 6.8.0-2045.46 Available with Ubuntu Pro linux-image-6.8.1-1051-realtime 6.8.1-1051.52 Available with Ubuntu Pro linux-image-aws-6.8 6.8.0-1055.58 linux-image-aws-64k-6.8 6.8.0-1055.58 linux-image-aws-64k-lts-24.04 6.8.0-1055.58 linux-image-aws-fips 6.8.0-1055.58+fips1 Available with Ubuntu Pro linux-image-aws-fips-6.8 6.8.0-1055.58+fips1 Available with Ubuntu Pro linux-image-aws-lts-24.04 6.8.0-1055.58 linux-image-gcp-6.8 6.8.0-1058.61 linux-image-gcp-64k-6.8 6.8.0-1058.61 linux-image-gcp-64k-lts-24.04 6.8.0-1058.61 linux-image-gcp-fips 6.8.0-1058.61+fips1 Available with Ubuntu Pro linux-image-gcp-fips-6.8 6.8.0-1058.61+fips1 Available with Ubuntu Pro linux-image-gcp-lts-24.04 6.8.0-1058.61 linux-image-generic 6.8.0-117.117 linux-image-generic-6.8 6.8.0-117.117 linux-image-generic-64k 6.8.0-117.117 linux-image-generic-64k-6.8 6.8.0-117.117 linux-image-generic-lpae 6.8.0-117.117 linux-image-gke 6.8.0-1054.60 linux-image-gke-6.8 6.8.0-1054.60 linux-image-gke-64k 6.8.0-1054.60 linux-image-gke-64k-6.8 6.8.0-1054.60 linux-image-gkeop 6.8.0-1041.44 linux-image-gkeop-6.8 6.8.0-1041.44 linux-image-ibm 6.8.0-1055.56 linux-image-ibm-6.8 6.8.0-1055.56 linux-image-ibm-classic 6.8.0-1055.56 linux-image-ibm-lts-24.04 6.8.0-1055.56 linux-image-intel-iot-realtime 6.8.1-1051.52 Available with Ubuntu Pro linux-image-intel-iotg 6.8.0-117.117 linux-image-kvm 6.8.0-117.117 linux-image-lowlatency 6.8.0-117.117.1 linux-image-lowlatency-6.8 6.8.0-117.117.1 linux-image-lowlatency-64k 6.8.0-117.117.1 linux-image-lowlatency-64k-6.8 6.8.0-117.117.1 linux-image-raspi 6.8.0-1056.60 linux-image-raspi-6.8 6.8.0-1056.60 linux-image-raspi-realtime 6.8.0-2045.46 Available with Ubuntu Pro linux-image-raspi-realtime-6.8 6.8.0-2045.46 Available with Ubuntu Pro linux-image-realtime 6.8.1-1051.52 Available with Ubuntu Pro linux-image-realtime-6.8.1 6.8.1-1051.52 Available with Ubuntu Pro linux-image-virtual 6.8.0-117.117 linux-image-virtual-6.8 6.8.0-117.117 Ubuntu 22.04 LTS linux-image-6.8.0-1055-ibm 6.8.0-1055.56~22.04.1 linux-image-6.8.0-117-lowlatency 6.8.0-117.117.1~22.04.1 linux-image-6.8.0-117-lowlatency-64k 6.8.0-117.117.1~22.04.1 linux-image-6.8.1-1051-realtime 6.8.1-1051.52~22.04.1 Available with Ubuntu Pro linux-image-ibm-6.8 6.8.0-1055.56~22.04.1 linux-image-lowlatency-6.8 6.8.0-117.117.1~22.04.1 linux-image-lowlatency-64k-6.8 6.8.0-117.117.1~22.04.1 linux-image-lowlatency-64k-hwe-22.04 6.8.0-117.117.1~22.04.1 linux-image-lowlatency-hwe-22.04 6.8.0-117.117.1~22.04.1 linux-image-realtime-6.8.1 6.8.1-1051.52~22.04.1 Available with Ubuntu Pro linux-image-realtime-hwe-22.04 6.8.1-1051.52~22.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standardkernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8278-1 CVE-2024-50004, CVE-2024-58096, CVE-2024-58097, CVE-2025-37926, CVE-2025-38201, CVE-2025-38591, CVE-2025-40039, CVE-2025-40082, CVE-2025-40149, CVE-2025-68351, CVE-2025-68358, CVE-2025-68365, CVE-2025-68725, CVE-2025-68749, CVE-2025-68803, CVE-2025-68823, CVE-2025-71160, CVE-2025-71162, CVE-2025-71163, CVE-2025-71180, CVE-2025-71182, CVE-2025-71183, CVE-2025-71184, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71192, CVE-2025-71193, CVE-2025-71194, CVE-2025-71195, CVE-2025-71196, CVE-2025-71197, CVE-2025-71198, CVE-2025-71199, CVE-2025-71200, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2025-71225, CVE-2025-71268, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22994, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23000, CVE-2026-23001, CVE-2026-23003, CVE-2026-23005, CVE-2026-23006, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23020, CVE-2026-23021, CVE-2026-23025, CVE-2026-23026, CVE-2026-23030, CVE-2026-23031, CVE-2026-23032, CVE-2026-23033, CVE-2026-23035, CVE-2026-23037, CVE-2026-23038, CVE-2026-23047, CVE-2026-23049, CVE-2026-23050, CVE-2026-23053, CVE-2026-23054, CVE-2026-23056, CVE-2026-23057, CVE-2026-23058, CVE-2026-23059, CVE-2026-23061, CVE-2026-23062, CVE-2026-23063, CVE-2026-23064, CVE-2026-23065, CVE-2026-23068, CVE-2026-23069, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23086, CVE-2026-23087, CVE-2026-23088, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23094, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23102, CVE-2026-23103, CVE-2026-23105, CVE-2026-23107, CVE-2026-23108, CVE-2026-23110, CVE-2026-23113, CVE-2026-23116, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23123, CVE-2026-23124, CVE-2026-23125, CVE-2026-23126, CVE-2026-23128, CVE-2026-23129, CVE-2026-23131, CVE-2026-23133, CVE-2026-23135, CVE-2026-23136, CVE-2026-23139, CVE-2026-23140, CVE-2026-23141, CVE-2026-23142, CVE-2026-23144, CVE-2026-23145, CVE-2026-23146, CVE-2026-23148, CVE-2026-23150, CVE-2026-23151, CVE-2026-23156, CVE-2026-23159, CVE-2026-23160, CVE-2026-23163, CVE-2026-23164, CVE-2026-23166, CVE-2026-23167, CVE-2026-23168, CVE-2026-23170, CVE-2026-23172, CVE-2026-23173, CVE-2026-23176, CVE-2026-23178, CVE-2026-23179, CVE-2026-23180, CVE-2026-23182, CVE-2026-23187, CVE-2026-23190, CVE-2026-23191, CVE-2026-23193, CVE-2026-23198, CVE-2026-23200, CVE-2026-23202, CVE-2026-23204, CVE-2026-23205, CVE-2026-23206, CVE-2026-23212, CVE-2026-23213, CVE-2026-23214, CVE-2026-23215, CVE-2026-23216, CVE-2026-23254, CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23260, CVE-2026-23261, CVE-2026-23262, CVE-2026-23264, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078 Package Information: https://launchpad.net/ubuntu/+source/linux/6.8.0-117.117 https://launchpad.net/ubuntu/+source/linux-aws/6.8.0-1055.58 https://launchpad.net/ubuntu/+source/linux-aws-fips/6.8.0-1055.58+fips1 https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1058.61 https://launchpad.net/ubuntu/+source/linux-gcp-fips/6.8.0-1058.61+fips1 https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1054.60 https://launchpad.net/ubuntu/+source/linux-gkeop/6.8.0-1041.44 https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1055.56 https://launchpad.net/ubuntu/+source/linux-lowlatency/6.8.0-117.117.1 https://launchpad.net/ubuntu/+source/linux-raspi/6.8.0-1056.60 https://launchpad.net/ubuntu/+source/linux-raspi-realtime/6.8.0-2045.46 https://launchpad.net/ubuntu/+source/linux-realtime/6.8.1-1051.52 https://launchpad.net/ubuntu/+source/linux-ibm-6.8/6.8.0-1055.56~22.04.1 https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-6.8/6.8.0-117.117.1~22.04.1 https://launchpad.net/ubuntu/+source/linux-realtime-6.8/6.8.1-1051.52~22.04.1 . Multiple security issues fixed in the Linux kernel for Ubuntu addressing potential privilege escalation risks and system stability.. Linux Kernel Update, Ubuntu Security Fix, Privilege Escalation, Kernel Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8277-1 May 19, 2026 linux, linux-aws, linux-hwe-6.17, linux-oem-6.17, linux-oracle, linux-raspi, linux-realtime, linux-realtime-6.17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-realtime: Linux kernel for Real-time systems - linux-hwe-6.17: Linux hardware enablement (HWE) kernel - linux-oem-6.17: Linux kernel for OEM systems - linux-realtime-6.17: Linux kernel for Real-time systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - S390 architecture; - Cryptographic API; - GPU drivers; - Ethernet bonding driver; - Network file system (NFS) server daemon; - Distributed Switch Architecture; - Netfilter; - Control group (cgroup); - Kernel kexec() syscall; - Memory management; - MAC80211 subsystem; - Multipath TCP; - Packet sockets; - TLS protocol; - Unix domain sockets; (CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394,CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 linux-image-6.17.0-1013-realtime 6.17.0-1013.15 linux-image-6.17.0-1014-oracle 6.17.0-1014.14 linux-image-6.17.0-1014-oracle-64k 6.17.0-1014.14 linux-image-6.17.0-1015-aws 6.17.0-1015.15 linux-image-6.17.0-1015-aws-64k 6.17.0-1015.15 linux-image-6.17.0-1017-raspi 6.17.0-1017.17 linux-image-6.17.0-29-generic 6.17.0-29.29 linux-image-6.17.0-29-generic-64k 6.17.0-29.29 linux-image-aws 6.17.0-1015.15 linux-image-aws-6.17 6.17.0-1015.15 linux-image-aws-64k 6.17.0-1015.15 linux-image-aws-64k-6.17 6.17.0-1015.15 linux-image-generic 6.17.0-29.29 linux-image-generic-6.17 6.17.0-29.29 linux-image-generic-64k 6.17.0-29.29 linux-image-generic-64k-6.17 6.17.0-29.29 linux-image-oracle 6.17.0-1014.14 linux-image-oracle-6.17 6.17.0-1014.14 linux-image-oracle-64k 6.17.0-1014.14 linux-image-oracle-64k-6.17 6.17.0-1014.14 linux-image-raspi 6.17.0-1017.17 linux-image-raspi-6.17 6.17.0-1017.17 linux-image-realtime 6.17.0-1013.15 linux-image-realtime-6.17 6.17.0-1013.15 linux-image-realtime-hwe-24.04 6.17.0-1013.15 linux-image-realtime-hwe-24.04-edge 6.17.0-1013.15 linux-image-virtual 6.17.0-29.29 linux-image-virtual-6.17 6.17.0-29.29 Ubuntu 24.04 LTS linux-image-6.17.0-1013-realtime 6.17.0-1013.15~24.04.1 Available with Ubuntu Pro linux-image-6.17.0-1023-oem 6.17.0-1023.23 linux-image-6.17.0-29-generic 6.17.0-29.29~24.04.1 linux-image-6.17.0-29-generic-64k 6.17.0-29.29~24.04.1 linux-image-generic-6.17 6.17.0-29.29~24.04.1 linux-image-generic-64k-6.17 6.17.0-29.29~24.04.1 linux-image-generic-64k-hwe-24.04 6.17.0-29.29~24.04.1 linux-image-generic-hwe-24.04 6.17.0-29.29~24.04.1 linux-image-oem-24.04 6.17.0-1023.23 linux-image-oem-24.04a 6.17.0-1023.23 linux-image-oem-24.04b 6.17.0-1023.23 linux-image-oem-24.04c 6.17.0-1023.23 linux-image-oem-24.04d 6.17.0-1023.23 linux-image-oem-6.17 6.17.0-1023.23 linux-image-realtime-6.17 6.17.0-1013.15~24.04.1 Available with Ubuntu Pro linux-image-realtime-hwe-24.04 6.17.0-1013.15~24.04.1 Available with Ubuntu Pro linux-image-virtual-6.17 6.17.0-29.29~24.04.1 linux-image-virtual-hwe-24.04 6.17.0-29.29~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8277-1 CVE-2025-71088, CVE-2025-71090, CVE-2025-71127, CVE-2025-71134, CVE-2025-71139, CVE-2025-71141, CVE-2025-71142, CVE-2025-71144, CVE-2025-71152, CVE-2025-71155, CVE-2026-23274, CVE-2026-23351, CVE-2026-23394, CVE-2026-31419, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078 Package Information: https://launchpad.net/ubuntu/+source/linux/6.17.0-29.29 https://launchpad.net/ubuntu/+source/linux-aws/6.17.0-1015.15 https://launchpad.net/ubuntu/+source/linux-oracle/6.17.0-1014.14 https://launchpad.net/ubuntu/+source/linux-raspi/6.17.0-1017.17 https://launchpad.net/ubuntu/+source/linux-realtime/6.17.0-1013.15 https://launchpad.net/ubuntu/+source/linux-hwe-6.17/6.17.0-29.29~24.04.1 https://launchpad.net/ubuntu/+source/linux-oem-6.17/6.17.0-1023.23 https://launchpad.net/ubuntu/+source/linux-realtime-6.17/6.17.0-1013.15~24.04.1 . Critical security issues in the Linux kernel patched for Ubuntu 25.10 and 24.04 LTS. Escalate privilege risk fixed!. Linux kernel security, Ubuntu security update, critical patches. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:1671-2 Release Date: 2026-05-04T09:19:32Z Rating: important References: * bsc#1262573 Cross-References: * CVE-2026-31431 CVSS scores: * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: The SUSE Linux Enterprise 15 SP5 kernel was updated to fix one security issue The following security issue was fixed: * CVE-2026-31431: The copy.fail security issue is fixed by revert to operating out-of-place in algif_aead (bsc#1262573). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-1671=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150600.23.100.1 * kernel-default-debuginfo-6.4.0-150600.23.100.1 * kernel-default-extra-debuginfo-6.4.0-150600.23.100.1 * kernel-default-debugsource-6.4.0-150600.23.100.1 * kernel-syms-6.4.0-150600.23.100.1 * ocfs2-kmp-default-debuginfo-6.4.0-150600.23.100.1 * gfs2-kmp-default-6.4.0-150600.23.100.1 * kernel-default-optional-debuginfo-6.4.0-150600.23.100.1 * kselftests-kmp-default-debuginfo-6.4.0-150600.23.100.1 * cluster-md-kmp-default-6.4.0-150600.23.100.1 * kernel-obs-qa-6.4.0-150600.23.100.1 * kernel-default-devel-6.4.0-150600.23.100.1 * dlm-kmp-default-debuginfo-6.4.0-150600.23.100.1 * dlm-kmp-default-6.4.0-150600.23.100.1 *kernel-obs-build-debugsource-6.4.0-150600.23.100.1 * cluster-md-kmp-default-debuginfo-6.4.0-150600.23.100.1 * kernel-default-devel-debuginfo-6.4.0-150600.23.100.1 * reiserfs-kmp-default-6.4.0-150600.23.100.1 * gfs2-kmp-default-debuginfo-6.4.0-150600.23.100.1 * kselftests-kmp-default-6.4.0-150600.23.100.1 * ocfs2-kmp-default-6.4.0-150600.23.100.1 * kernel-default-livepatch-6.4.0-150600.23.100.1 * kernel-default-optional-6.4.0-150600.23.100.1 * kernel-default-extra-6.4.0-150600.23.100.1 * reiserfs-kmp-default-debuginfo-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (nosrc ppc64le x86_64) * kernel-debug-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (ppc64le x86_64) * kernel-debug-devel-debuginfo-6.4.0-150600.23.100.1 * kernel-debug-debugsource-6.4.0-150600.23.100.1 * kernel-debug-debuginfo-6.4.0-150600.23.100.1 * kernel-debug-devel-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (x86_64) * kernel-debug-vdso-debuginfo-6.4.0-150600.23.100.1 * kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.100.1 * kernel-default-vdso-6.4.0-150600.23.100.1 * kernel-debug-vdso-6.4.0-150600.23.100.1 * kernel-kvmsmall-vdso-6.4.0-150600.23.100.1 * kernel-default-vdso-debuginfo-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-debuginfo-6.4.0-150600.23.100.1 * kernel-default-base-6.4.0-150600.23.100.1.150600.12.46.2 * kernel-kvmsmall-devel-6.4.0-150600.23.100.1 * kernel-kvmsmall-debugsource-6.4.0-150600.23.100.1 * kernel-default-base-rebuild-6.4.0-150600.23.100.1.150600.12.46.2 * kernel-kvmsmall-debuginfo-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-default-livepatch-devel-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (noarch) * kernel-devel-6.4.0-150600.23.100.1 * kernel-docs-html-6.4.0-150600.23.100.1 * kernel-source-6.4.0-150600.23.100.1 *kernel-macros-6.4.0-150600.23.100.1 * kernel-source-vanilla-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (noarch nosrc) * kernel-docs-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (nosrc s390x) * kernel-zfcpdump-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (s390x) * kernel-zfcpdump-debuginfo-6.4.0-150600.23.100.1 * kernel-zfcpdump-debugsource-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (aarch64) * cluster-md-kmp-64kb-6.4.0-150600.23.100.1 * gfs2-kmp-64kb-debuginfo-6.4.0-150600.23.100.1 * dtb-nvidia-6.4.0-150600.23.100.1 * dtb-allwinner-6.4.0-150600.23.100.1 * kselftests-kmp-64kb-6.4.0-150600.23.100.1 * kernel-64kb-debugsource-6.4.0-150600.23.100.1 * kernel-64kb-extra-debuginfo-6.4.0-150600.23.100.1 * dtb-amlogic-6.4.0-150600.23.100.1 * dtb-lg-6.4.0-150600.23.100.1 * dtb-qcom-6.4.0-150600.23.100.1 * kernel-64kb-devel-6.4.0-150600.23.100.1 * gfs2-kmp-64kb-6.4.0-150600.23.100.1 * dtb-marvell-6.4.0-150600.23.100.1 * dtb-cavium-6.4.0-150600.23.100.1 * dtb-renesas-6.4.0-150600.23.100.1 * dtb-sprd-6.4.0-150600.23.100.1 * dtb-socionext-6.4.0-150600.23.100.1 * dtb-amazon-6.4.0-150600.23.100.1 * ocfs2-kmp-64kb-6.4.0-150600.23.100.1 * cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.100.1 * dtb-apple-6.4.0-150600.23.100.1 * dtb-mediatek-6.4.0-150600.23.100.1 * dtb-xilinx-6.4.0-150600.23.100.1 * dtb-exynos-6.4.0-150600.23.100.1 * kernel-64kb-optional-debuginfo-6.4.0-150600.23.100.1 * dtb-arm-6.4.0-150600.23.100.1 * dlm-kmp-64kb-6.4.0-150600.23.100.1 * dtb-broadcom-6.4.0-150600.23.100.1 * dtb-amd-6.4.0-150600.23.100.1 * dlm-kmp-64kb-debuginfo-6.4.0-150600.23.100.1 * kernel-64kb-debuginfo-6.4.0-150600.23.100.1 * ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.100.1 * kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.100.1 * dtb-apm-6.4.0-150600.23.100.1 *reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.100.1 * dtb-rockchip-6.4.0-150600.23.100.1 * kernel-64kb-optional-6.4.0-150600.23.100.1 * kernel-64kb-devel-debuginfo-6.4.0-150600.23.100.1 * reiserfs-kmp-64kb-6.4.0-150600.23.100.1 * dtb-hisilicon-6.4.0-150600.23.100.1 * kernel-64kb-extra-6.4.0-150600.23.100.1 * dtb-freescale-6.4.0-150600.23.100.1 * dtb-altera-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (nosrc) * dtb-aarch64-6.4.0-150600.23.100.1 * openSUSE Leap 15.6 (aarch64 nosrc) * kernel-64kb-6.4.0-150600.23.100.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1262573 . An important SUSE update addresses the kernel's copy fail issue with CVE-2026-31431. Install the update now!. openSUSE kernel update important patch security fix. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50255 http://linux.oracle.com/errata/ELSA-2026-50255.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.354.4.2.el7uek.x86_64.rpm kernel-uek-container-5.4.17-2136.354.4.2.el7uek.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.354.4.2.el7uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.354.4.2.el7uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.354.4.2.el7uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.354.4.2.el7uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.354.4.2.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.354.4.2.el7uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-5.4.17-2136.354.4.2.el7uek.src.rpm Related CVEs: CVE-2026-31431 Description of changes: [5.4.17-2136.354.4.2] - crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39292250] - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39292250] - crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39292250] - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39292250] - crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39292250] - crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39292250] - crypto: algif_aead - Revert to operating out-of-place (Herbert Xu) [Orabug: 39292250] - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39292250] {CVE-2026-31431} - crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39292250] - crypto: doc - fix kernel-doc notation in chacha.c and af_alg.c (Randy Dunlap) [Orabug: 39292250] - x86/CPU: Fix FPDSS on Zen1 (Siddh Raman Pant) [Orabug:39292236] _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.