Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8633-2: Linux kernel vulnerabilities

A security problem was found in the Linux kernel's WiFi system that lets nearby attackers insert fake network packets. This issue arose because a previous fix did not work correctly. Additionally, many other security flaws were found in the Linux kernel that attackers could exploit to compromise systems running Ubuntu. These problems affect many parts of the Linux system. Ubuntu has released updates to fix these flaws. Users should update and reboot their systems to protect against possible attacks.

Published 13/8/2026, 9:44:52 pmVerified 13/8/2026, 11:26:34 pmRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

A security problem was found in the Linux kernel's WiFi system that lets nearby attackers insert fake network packets. This issue arose because a previous fix did not work correctly. Additionally, many other security flaws were found in the Linux kernel that attackers could exploit to compromise systems running Ubuntu. These problems affect many parts of the Linux system. Ubuntu has released updates to fix these flaws. Users should update and reboot their systems to protect against possible attacks.

Technical explanation

How the issue affects the environment

Researchers Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef identified a vulnerability in the Linux kernel's handling of aggregated WiFi frames within mesh networks. This was due to an incorrect patch for CVE-2020-24588, leading to CVE-2025-27558, where a physically proximate attacker can inject packets by exploiting this improper handling. Beyond this, multiple security vulnerabilities across various subsystems were discovered, including those in x86 architecture, cryptographic APIs, GPU and network drivers, NVME drivers, the Ext4 filesystem, IPv4 and IPv6 networking stacks, TCP and SCTP protocols, mesh networking protocols like B.A.T.M.A.N., and others. These vulnerabilities could enable attackers to compromise system integrity or availability if successfully exploited. The Ubuntu update addresses these flaws via updated kernel packages, requiring a system reboot and recompilation of third-party kernel modules due to ABI changes.

Operational impact

Why teams should care

The vulnerabilities can allow attackers with close physical presence to inject malicious network packets, potentially disrupting or taking over mesh network communications. Additionally, the wide range of other kernel vulnerabilities increases the risk of system compromise, jeopardizing data integrity, availability, and confidentiality. Organizations using Ubuntu systems may face increased risk of network attacks, system instability, or breaches if they do not apply the provided updates. Maintaining updated systems is critical to sustain operational security and trustworthiness.

Immediate action

Users should update their Linux kernel packages to the versions provided by Ubuntu in this advisory. After performing the update, a system reboot is required to apply all changes. Because of an ABI (Application Binary Interface) change, all third-party kernel modules installed must be recompiled and reinstalled to maintain compatibility after the update. Applying these updates helps protect systems from exploitation of the described vulnerabilities.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

The advisory does not specify any workarounds. Users should update and reboot their systems and recompile any third-party kernel modules.

Evidence and validation checklist

  • The WiFi subsystem in Linux kernel mishandles aggregated frames in mesh networks due to a flawed fix for CVE-2020-24588 (source: Ubuntu Security Notices).
  • A physically proximate attacker could exploit this to inject packets (CVE-2025-27558).
  • Numerous CVEs affecting various Linux kernel subsystems are listed, indicating a broad set of vulnerabilities.
  • Ubuntu released updated kernel package versions fixing these issues and requiring reboot and module recompilation.
  • Ubuntu advises applying updates and rebooting systems to mitigate the vulnerabilities.

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source