Ubuntu October kernel notices cover cloud, Pi, and IBM
Through 8 October 2026 Ubuntu patched multiple Linux kernels for Arm TLB, i.MX, AMD SEV-SNP, and networking flaws, with no exploitation reported.
Between 2 and 8 October 2026 Ubuntu published Linux kernel security notices for generic, Raspberry Pi, GCP, Oracle, Azure, AWS, and IBM packages. USN-8864-1 addresses CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221 in the NFS server, IPv6, and Netfilter, which Ubuntu says an attacker could possibly use to compromise a system. CVE-2025-10263, an Arm TLB invalidation issue that may let a local attacker write memory after permissions were revoked and escalate privileges, is cited for Raspberry Pi (USN-8871-1), GCP (USN-8878-1), Oracle (USN-8879-1), and IBM (USN-8906-1). CVE-2022-3114, a local i.MX clock-driver null-pointer crash, is named in USN-8875-1 and the GCP and Oracle notices, while CVE-2023-20585, an AMD RMP and IOMMU flaw affecting SEV-SNP guest memory integrity for a local attacker with hypervisor access, is covered by USN-8887-1, Azure USN-8888-1, AWS USN-8887-2, and Azure USN-8888-2. Additional architecture, driver, and filesystem fixes differ by kernel flavor; the notices do not contradict one another and none reports active exploitation.
- From 2 to 8 October 2026 Ubuntu issued kernel notices USN-8864-1, USN-8871-1 (Raspberry Pi), USN-8875-1, USN-8878-1 (GCP), USN-8879-1 (Oracle), USN-8887-1, USN-8888-1 (Azure), USN-8887-2 (AWS), USN-8888-2 (Azure), and USN-8906-1 (IBM).
- USN-8864-1 fixes CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221 in the NFS server, IPv6, and Netfilter; Ubuntu says an attacker could possibly compromise a system.
- CVE-2025-10263, an Arm broadcast TLB invalidation bug a local attacker might use to write memory after permissions were revoked and possibly escalate privileges, is named for Raspberry Pi, GCP, Oracle, and IBM.
- CVE-2022-3114, a local null-pointer crash in the i.MX clock driver, including after a memory-allocation failure per USN-8875-1, is named in USN-8875-1, GCP, and Oracle notices.
- CVE-2023-20585, flawed AMD Reverse Map Table checks on IOMMU access that a local hypervisor attacker could use to affect SEV-SNP guest memory integrity, is covered by USN-8887-1, USN-8888-1, AWS USN-8887-2, and Azure USN-8888-2.
- Other fixes, varying by notice, span ARM/ARM64/ARM32, MIPS, PowerPC, RISC-V, OpenRISC, x86, InfiniBand and network drivers, TCM, exFAT, NFS client, UAPI, User-Mode Linux, the block layer, crypto API, NVDIMM, Handshake API, and the Intel…
- None of the notices reports exploitation in the wild.
Coverage timelineoldest first · each row is one article
- · 6d agoUSN-8851-2: Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu Security Notices· 32
Ubuntu patched Raspberry Pi Linux kernel flaws in NFS, IPv6, and Netfilter that could compromise systems.
- · 6d agoUSN-8864-1: Linux kernel vulnerabilities
Ubuntu Security Notices· 36
Ubuntu patched Linux kernel flaws in NFS, IPv6, and Netfilter that could let an attacker compromise the system.
- · 3d agoUSN-8851-3: Linux kernel (Azure) vulnerabilities
Ubuntu Security Notices· 26
Ubuntu patched Linux kernel flaws in NFS, IPv6, and Netfilter for Azure kernels in USN-8851-3.
Vulnerabilities in this storyAll →
- CVE-2022-31145.5<1%An issue was discovered in the Linux kernel through 5.16-rc6published · linux linux kernel
- CVE-2023-205855.6<1%Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds…