Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities

This Ubuntu security advisory reports multiple vulnerabilities found in the Linux kernel, particularly for systems using Intel IoT and AMD processors, as well as various architectures and drivers. One notable issue in the NTFS file system code could let an attacker create a crafted file system image that reveals sensitive kernel memory when mounted. Other vulnerabilities affect AMD processors, potentially allowing local attackers to access sensitive information or escalate privileges. The update addresses numerous flaws across many subsystems and drivers, improving overall system security.

Published 31/7/2026, 9:40:09 amVerified 31/7/2026, 10:13:09 amRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

This Ubuntu security advisory reports multiple vulnerabilities found in the Linux kernel, particularly for systems using Intel IoT and AMD processors, as well as various architectures and drivers. One notable issue in the NTFS file system code could let an attacker create a crafted file system image that reveals sensitive kernel memory when mounted. Other vulnerabilities affect AMD processors, potentially allowing local attackers to access sensitive information or escalate privileges. The update addresses numerous flaws across many subsystems and drivers, improving overall system security.

Technical explanation

How the issue affects the environment

The advisory details several Linux kernel vulnerabilities affecting Intel IoT platforms and AMD processors, among other components. Specifically, CVE-2023-45896 involves improper validation of file name lengths in the NTFS file system implementation, resulting in an out-of-bounds read that can leak kernel memory when a malicious NTFS image is mounted and manipulated. CVE-2025-54505 points to AMD processors improperly clearing data in the floating point divider unit during speculative execution, allowing local attackers to expose sensitive data. CVE-2025-54518 describes AMD Zen 2 processors failing to isolate shared operation cache resources, which could permit local attackers to corrupt higher privilege instructions and elevate privileges. The advisory further notes fixes for multiple other security issues across a wide range of kernel subsystems, architectures (ARM32, ARM64, MIPS, PowerPC, S390, x86), drivers (network, storage, USB, Bluetooth, audio, etc.), filesystems (BTRFS, Ceph, Ext4, F2FS, FAT, NTFS3, XFS, etc.), and kernel features (memory management, scheduling, cryptography, security modules, networking, etc.).

Operational impact

Why teams should care

Systems using affected Linux kernel versions, especially on Intel IoT platforms or with AMD processors, may be vulnerable to local or remote attacks leading to unauthorized information disclosure or privilege escalation. Exploitation could expose sensitive kernel memory or compromise system integrity. Applying the updates is vital for mitigating these risks and maintaining system security and reliability.

Immediate action

The advisory recommends updating the system's Linux kernel packages to the fixed package versions listed for Ubuntu 22.04 LTS and 20.04 LTS Intel IoT kernels. After performing the standard system update, a reboot is necessary to apply all changes. Due to an ABI change, third-party kernel modules must be recompiled and reinstalled. The updates can be obtained via standard Ubuntu package management tools and Ubuntu Pro subscription services.

Affected and fixed releases

Affected versionsNot specified in the advisory
Fixed versionsNot specified in the advisory

Temporary risk reduction

The advisory does not specify any workarounds. Applying the vendor-provided patches and performing a system reboot are necessary to address the vulnerabilities.

Evidence and validation checklist

  • Advisory published by Ubuntu Security Notices (USN-8620-3)
  • Description of CVE-2023-45896 concerning NTFS file system out-of-bounds read
  • Description of CVE-2025-54505 concerning speculative execution data leakage on AMD processors
  • Description of CVE-2025-54518 concerning privilege escalation on AMD Zen 2 processors
  • Details on multiple Linux kernel subsystems affected
  • Instructions for updating kernel packages and recompiling third-party modules

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source