Ubuntu patches Raspberry Pi kernel flaws in two notices
Ubuntu patched Raspberry Pi Linux kernels in USN-8668-2 and USN-8661-5, covering NTFS reads, an AMD speculative leak, and Wi-Fi mesh packet injection.
Ubuntu published two security notices for the Linux kernel on Raspberry Pi. USN-8668-2, dated 2026-09-21, addresses CVE-2023-45896, an out-of-bounds read in the NTFS implementation that malicious NTFS images can trigger and that may expose kernel memory, and CVE-2025-54505, in which certain AMD processors do not properly clear data during speculative execution so a local attacker can expose sensitive information. USN-8661-5, dated 2026-09-22, addresses CVE-2025-27558, an incomplete fix for CVE-2020-24588 in which the Wi-Fi stack mishandles aggregated frames in mesh networks, letting a physically nearby attacker inject packets. That notice also covers flaws in x86, InfiniBand, network and NVMe drivers, ext4, SMB, IPv4, traffic control, TCP, and kernel locking, which Ubuntu says an attacker could possibly use to compromise a system. Patches are available for affected systems. The notices cover different issues and do not contradict each other.
- USN-8668-2 (2026-09-21) patches the Raspberry Pi Linux kernel.
- CVE-2023-45896 is an NTFS out-of-bounds read via malicious images that can expose kernel memory.
- CVE-2025-54505: certain AMD processors do not properly clear data during speculative execution, letting a local attacker expose sensitive information.
- USN-8661-5 (2026-09-22) also updates the Raspberry Pi Linux kernel.
- CVE-2025-27558 is an incomplete fix for CVE-2020-24588: the Wi-Fi stack mishandles aggregated frames in mesh networks, allowing a physically nearby attacker to inject packets.
- USN-8661-5 also covers flaws in x86, InfiniBand, network and NVMe drivers, ext4, SMB, IPv4, traffic control, TCP, and kernel locking that Ubuntu says could possibly let an attacker compromise a system.
- Patches are available for affected systems.
Coverage timelineoldest first · each row is one article
- · 5d agoUSN-8668-2: Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu Security Notices· 55
Ubuntu patches Linux kernel vulnerabilities for Raspberry Pi, including an NTFS flaw and an AMD processor speculative execution issue.
- · 4d agoUSN-8661-5: Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu Security Notices· 27
Ubuntu patches Raspberry Pi Linux kernel flaws, including Wi-Fi mesh packet injection CVE-2025-27558.
Vulnerabilities in this storyAll →
- CVE-2020-245883.54%The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the…published · ieee ieee 802.11 PoC