Critical Linux Kernel Vulnerabilities Expose Systems Across Architectures
Multiple high-severity flaws in the Linux kernel affect NFS, Netfilter, and IPv6 subsystems. Patches are available across Ubuntu security notices.
TL;DR
- Several Linux kernel vulnerabilities allow attackers to compromise systems.
- Impacted subsystems include NFS, Netfilter, IPv6, and various network/file system components.
- ARM64, x86, and other architectures are affected.
- CVEs addressed include CVE-2025-38724, CVE-2026-53131, CVE-2026-53221, and others.
- Organizations should apply updates from Ubuntu immediately.
Multiple critical vulnerabilities have been identified in the Linux kernel that could allow attackers to compromise systems across various hardware architectures. These flaws span key subsystems such as NFS, Netfilter, IPv6 networking, and more, increasing the risk of privilege escalation and memory protection bypasses.
Ubuntu has released several security updates addressing these issues across its distributions, including standard kernels, GKE editions, FIPS-compliant versions, and Raspberry Pi builds. Organizations running Linux-based workloads should prioritize applying the relevant patches.
Affected Subsystems and Attack Vectors
- Network File System (NFS) clients and servers are vulnerable to exploitation.
- Netfilter and IPv6 networking components contain flaws that may lead to system compromise.
- Memory protection bypasses possible via ARM64 TLB invalidation issues (CVE-2025-10263).
- Drivers for InfiniBand, NVME, MANA, and Virtio are impacted.
- File systems including NTFS3, OCFS2, and exFAT have reported vulnerabilities.
Supported Architectures and Distributions
- ARM64, x86, and s390 architectures are among those affected.
- Specific kernel variants like GKE, FIPS, and Raspberry Pi also require patching.
- Cloud environments using Xen or Microsoft Azure drivers are at risk.
- Distributed storage solutions leveraging DRBD may be impacted.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.