It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container….
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500, CVE-2026-45998, CVE-2026-46000)
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503,
CVE-2026-46300)
Qualys discovered that a race condition existed in the ptrace subsystem of
the Linux kernel when privileged processes are exiting. An unprivileged
local attacker could use this issue to expose sensitive information.
(CVE-2026-46333)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a memory leak when handling AppArmor notifications. A local
attacker could use this to cause resource exhaustion. (CVE-2026-47326)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a NULL pointer dereference when handling AppArmor notifications. A
local attacker could use this to cause a kernel oops. (CVE-2026-47327)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an invalid free when handling AppArmor notifications. A local
attacker could use this to corrupt kernel memory. (CVE-2026-47328)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained insufficient validation of AppArmor notification responses. A
local attacker could use this to allow crafted responses to be processed.
(CVE-2026-47329)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 used
an uninitialized variable when handling AppArmor notifications. A local
attacker could use this to cause incorrect caching of data.
(CVE-2026-47330)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause information disclosure of kernel
memory. (CVE-2026-47332)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained a out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause kernel memory corruption and,
theoretically, influence processing of AppArmor policies. (CVE-2026-47333)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained incorrect holding of locks when handling AppArmor notifications.
A local attacker could use this to cause a kernel panic or deadlock.
(CVE-2026-47334)
Tristan Madani and Trevor Lawrence have each independently discovered that
Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a NULL pointer dereference
when handling AppArmor network socket mediation. A local attacker could use
this to cause a kernel oops. (CVE-2026-47337)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD Distributed Replicated Block Device drivers;
- Rados block device (RBD) driver;
- Ublk userspace block driver;
- Compressed RAM block device driver;
- Bluetooth drivers;
- Bus devices;
- Character device driver;
- TPM device driver;
- Clock framework and drivers;
- CPU frequency scaling framework;
- Hardware crypto device drivers;
- EDAC drivers;
- EFI core;
- FWCTL subsystem;
- GPU drivers;
- Greybus drivers;
- HID subsystem;
- Microsoft Hyper-V drivers;
- Hardware monitoring drivers;
- I2C subsystem;
- I3C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- Input Device core drivers;
- IOMMU subsystem;
- LED subsystem;
- Mailbox framework;
- Multiple devices driver;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- IBM Advanced System Management driver;
- MTD block device drivers;
- Network drivers;
- Ethernet bonding driver;
- Mellanox network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- STMicroelectronics network drivers;
- MediaTek network drivers;
- NTB driver;
- NVME drivers;
- Device tree and open firmware driver;
- PCI subsystem;
- Pin controllers subsystem;
- Chrome hardware platform drivers;
- ACPI WMI driver;
- x86 platform drivers;
- Generic PM domains;
- MediaTek PM domains;
- Power supply drivers;
- Remote Processor subsystem;
- MPAM driver;
- Amlogic Meson reset controller drivers;
- S/390 drivers;
- SCSI subsystem;
- NVIDIA Tegra Control Backbone (CBB) driver;
- SPI subsystem;
- Greybus lights staging drivers;
- Media staging drivers;
- Realtek RTL8723BS SDIO drivers;
- SM750 framebuffer staging driver;
- TCM subsystem;
- Thermal drivers;
- TTY drivers;
- USB Device Class drivers;
- ULPI bus;
- USB Gadget drivers;
- USB Type-C support driver;
- TI TPS6598x USB Power Delivery controller driver;
- USB over IP driver;
- vDPA drivers;
- VFIO drivers;
- Framebuffer layer;
- TSM AMD SEV Guest driver;
- Xen hypervisor drivers;
- 9P distributed file system;
- File systems infrastructure;
- AFS file system;
- BTRFS file system;
- Ceph distributed file system;
- EROFS file system;
- Ext4 file system;
- F2FS file system;
- FUSE (File system in Userspace);
- GFS2 file system;
- HFS+ file system;
- HugeTLB file system;
- Journaling layer for block devices (JBD2);
- Network file system (NFS) server daemon;
- NILFS2 file system;
- File system notification infrastructure;
- NTFS3 file system;
- OCFS2 file system;
- Overlay file system;
- Diskquota system;
- SMB network file system;
- Tracing file system;
- UDF file system;
- XFS file system;
- DRM TTM subsystem;
- Codetag library;
- Control group (cgroup);
- Kernel CPU control infrastructure;
- Memory management;
- QorIQ DPAA2 FSL-MC bus driver;
- Freescale ENETC Ethernet drivers;
- Memory Management;
- KVM subsystem;
- padata parallel execution mechanism;
- PPP protocol drivers and compressors;
- Bluetooth subsystem;
- Networking core;
- Netfilter;
- Network traffic control;
- Tracing infrastructure;
- User-space API (UAPI);
- io_uring subsystem;
- IPC subsystem;
- Audit subsystem;
- BPF subsystem;
- Kernel exit() syscall;
- Kernel fork() syscall;
- Kernel futex primitives;
- Locking primitives;
- Padata parallel execution mechanism;
- Scheduler infrastructure;
- Timer subsystem;
- Cryptographic library;
- Scatterlist API;
- Heterogeneous memory management;
- KASAN memory debugging framework;
- 802.1Q VLAN protocol;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- CAIF protocol;
- CAN network layer;
- Ceph Core library;
- Distributed Switch Architecture;
- IPv4 networking;
- IPv6 networking;
- MAC80211 subsystem;
- Multipath TCP;
- NFC subsystem;
- Open vSwitch;
- Packet sockets;
- Phonet protocol;
- Qualcomm IPC Router (QRTR);
- RDS protocol;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
- Stream parser;
- TIPC protocol;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- XFRM subsystem;
- Integrity Measurement Architecture(IMA) framework;
- Landlock security;
- SELinux security module;
- ALSA framework;
- Generic PCM loopback sound driver;
- FireWire sound drivers;
- HD-audio driver;
- Creative Sound Blaster X-Fi driver;
- QCOM ASoC drivers;
- SOF drivers;
- STI ASoC drivers;
- USB sound devices;
- Objtool