Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8887-3: Linux kernel vulnerabilities

A number of security weaknesses were found in the Linux kernel affecting many parts of the system, including a specific issue on some AMD processors that could let an attacker with hypervisor access exploit memory protections for virtual machines. These flaws could allow attackers to compromise system security. Users are advised to update their Linux kernel to the versions that include these corrections.

QCS published 11/10/2026, 8:51:52 am ISTVendor disclosure 9/10/2026, 2:08:46 pm ISTVerified 11/10/2026, 8:51:52 am ISTRevision 1

In plain language

What this advisory means

A number of security weaknesses were found in the Linux kernel affecting many parts of the system, including a specific issue on some AMD processors that could let an attacker with hypervisor access exploit memory protections for virtual machines. These flaws could allow attackers to compromise system security. Users are advised to update their Linux kernel to the versions that include these corrections.

Technical explanation

How the issue affects the environment

An issue was discovered where certain AMD processors did not correctly perform Reverse Map Table (RMP) checks when the Input-Output Memory Management Unit (IOMMU) accessed specific host buffers. This vulnerability (CVE-2023-20585) could be exploited by a local attacker with hypervisor access to cause out-of-bounds memory access, potentially compromising the integrity of SEV-SNP (Secure Encrypted Virtualization-Secure Nested Paging) guest memory. Additionally, multiple other security vulnerabilities affecting a broad range of Linux kernel subsystems—including various architectures (ARM64, ARM32, MIPS, OpenRISC, PowerPC, RISC-V, S390, x86), driver subsystems (network, storage, GPU, USB, ACPI, Bluetooth, among others), file systems, cryptographic components, and kernel mechanisms—were identified. An attacker with appropriate access could use these flaws to compromise system integrity or availability. The update includes fixes for these vulnerabilities across these many subsystems within the Linux kernel.

Operational impact

Why teams should care

If exploited, these vulnerabilities could allow attackers to undermine system security across a wide range of environments, including cloud and virtualization platforms. This could lead to unauthorized data access, denial of service, or further compromise of systems that rely on the Linux kernel, negatively impacting business operations and trust. The issue with AMD processors could particularly affect virtualized environments using SEV-SNP technology, risking guest memory integrity under local hypervisor attackers.

Immediate action

Users should update their systems to the fixed kernel package versions provided by the Ubuntu update to mitigate the vulnerabilities. This includes upgrading to updated linux-image packages as listed in the advisory. Because the kernel upgrade involves an ABI change, recompilation and reinstallation of third-party kernel modules may be necessary. A system reboot is required to apply the changes and ensure vulnerabilities are mitigated.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionslinux-image-7.0.0-1013.13~24.04.1, linux-image-7.0.0-1014.14~24.04.1, linux-image-7.0.0-38.38~24.04.4

Temporary risk reduction

The advisory does not specify any workaround. System administrators should apply the provided kernel updates to remediate the issues.

Evidence and validation checklist

  • Vendor Ubuntu Security Notice USN-8887-3
  • Specific mention of CVE-2023-20585 on AMD RMP checks and IOMMU use
  • Listing of numerous kernel subsystems affected
  • Recommendation to update to fixed kernel versions
  • Mention of an ABI change requiring module recompilation and reboot

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source