← Back to blog

Critical Linux Kernel Vulnerabilities Patched Across Ubuntu Releases

Multiple high-severity flaws in the Linux kernel impact core subsystems including networking, file systems, and device drivers. Patches are available for Ubuntu systems.

TL;DR

  • Ubuntu released updates fixing over 20 critical Linux kernel vulnerabilities.
  • Flaws affect key subsystems like ARM64, NFS, IPv4/IPv6, and USB over IP.
  • Exploitation could lead to system compromise or privilege escalation.
  • Two related security notices issued: USN-8490-1 and USN-8490-2.
  • Organizations using Ubuntu should apply patches immediately.

A significant number of vulnerabilities have been identified and patched in the Linux kernel, impacting Ubuntu systems across multiple architectures and subsystems. These flaws span low-level components such as ARM64 architecture, block layer functionality, cryptographic APIs, and various network and file system implementations.

The vulnerabilities pose risks that include potential system compromise, unauthorized access, and privilege escalation. Attackers may exploit these issues through local or remote means depending on the affected component. Organizations running Ubuntu-based systems are strongly advised to implement the provided updates without delay.

Canonical has published two related security advisories, USN-8490-1 and USN-8490-2, addressing identical sets of CVEs but targeting different Ubuntu release lines. This underscores the widespread nature of the risk across supported platforms.

Affected Subsystems and Components

  • Core kernel components including kthread helper and exit() syscall were impacted.
  • Networking layers such as IPv4, IPv6, Netfilter, and Multipath TCP contained exploitable flaws.
  • Storage-related modules including Ext4, NFS server daemon, and SCSI subsystem had vulnerabilities.
  • Device drivers for USB over IP, NVME, InfiniBand, and STMicroelectronics networks were affected.
  • File system infrastructure and distributed storage libraries like Ceph Core showed weaknesses.

Security Impact and Mitigation

  • Several CVEs included in the update allow for possible system compromise by attackers.
  • Privilege escalation and data exposure risks exist where flaws are left unpatched.
  • Both standard and real-time kernel variants required fixes indicating broad exposure.
  • Immediate deployment of Ubuntu security updates mitigates all reported vulnerabilities.
  • Administrators should verify patch installation and monitor for unusual activity post-update.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.