Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8619-1: Linux kernel (HWE) vulnerabilities

A number of security vulnerabilities were found in the Linux kernel used in Ubuntu. Some AMD processors had weaknesses that could let a local attacker access sensitive data, escalate privileges, or affect randomness used by security features. Additionally, many other issues affecting various hardware architectures, device drivers, and kernel subsystems were identified that could allow attackers to compromise the system. Ubuntu has provided updates to address these concerns, and users are recommended to update and reboot their systems to apply the fixes.

Published 28/7/2026, 7:28:45 amVerified 30/7/2026, 3:14:36 pmRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

A number of security vulnerabilities were found in the Linux kernel used in Ubuntu. Some AMD processors had weaknesses that could let a local attacker access sensitive data, escalate privileges, or affect randomness used by security features. Additionally, many other issues affecting various hardware architectures, device drivers, and kernel subsystems were identified that could allow attackers to compromise the system. Ubuntu has provided updates to address these concerns, and users are recommended to update and reboot their systems to apply the fixes.

Technical explanation

How the issue affects the environment

Multiple vulnerabilities were discovered in the Linux kernel, impacting several hardware architectures including ARM64, MIPS, PowerPC, RISC-V, S390, x86, and numerous kernel subsystems such as block layer, cryptographic API, various drivers (network, USB, GPU, Bluetooth, etc.), filesystems (BTRFS, Ext4, XFS, and others), kernel frameworks and APIs (io_uring, BPF, perf events), security frameworks (AppArmor, Landlock, LSM), and more. Specifically, on AMD processors: CVE-2025-54505 refers to improper clearing of data in the floating point divider unit during speculative execution, potentially leaking sensitive information; CVE-2025-54518 involves inadequate isolation of shared resources in the operation cache of AMD Zen 2 processors, possibly enabling privilege escalation via instruction corruption; CVE-2025-62626 concerns faulty entropy handling for RDSEED instruction on AMD Zen 5 processors, which could result in insufficient randomness affecting confidentiality and integrity. The update addresses these and many other kernel flaws to reduce system compromise risk.

Operational impact

Why teams should care

Exploitation of these vulnerabilities could lead to unauthorized access to sensitive data, privilege escalation, and system compromise, potentially impacting the confidentiality, integrity, and availability of business IT systems running Ubuntu. This poses risks for data breaches, service disruption, and loss of trust. Promptly applying updates reduces exposure and safeguards operations.

Immediate action

Apply the provided Linux kernel updates for your Ubuntu 22.04 LTS (HWE) system as soon as possible and reboot the machine to activate the fixes. Note that due to ABI changes in the kernel, third-party kernel modules may need to be recompiled and reinstalled after updating.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionslinux-image-6.8.0-136-generic 6.8.0-136.136~22.04.1

Temporary risk reduction

The Ubuntu security notice does not specify any workarounds. Users are advised to apply the kernel update and reboot to mitigate the vulnerabilities.

Evidence and validation checklist

  • The advisory is from Ubuntu Security Notices USN-8619-1 dated 28 July 2026.
  • The advisory details vulnerabilities in Linux kernel affecting multiple architectures and subsystems.
  • Specific AMD processor related vulnerabilities are CVE-2025-54505, CVE-2025-54518, and CVE-2025-62626.
  • The update corrects numerous kernel subsystem flaws.
  • Version linux-image-6.8.0-136-generic 6.8.0-136.136~22.04.1 is listed as the patched version.
  • The advisory recommends updating and rebooting systems.
  • No mention of known exploits or available workarounds besides patches.

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source