Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8905-2: Linux kernel (GCP) vulnerabilities

Multiple security vulnerabilities were found in the Linux kernel used on Google Cloud Platform (GCP) systems. These weaknesses affect many components, and an attacker could possibly use them to compromise a system. The issue has been addressed by Ubuntu in a security update that fixes flaws across a wide range of hardware architectures and drivers, including network, USB, file system, memory management, and many others.

QCS published 11/10/2026, 11:42:09 pm ISTVendor disclosure 9/10/2026, 2:08:26 pm ISTVerified 11/10/2026, 11:42:09 pm ISTRevision 1

In plain language

What this advisory means

Multiple security vulnerabilities were found in the Linux kernel used on Google Cloud Platform (GCP) systems. These weaknesses affect many components, and an attacker could possibly use them to compromise a system. The issue has been addressed by Ubuntu in a security update that fixes flaws across a wide range of hardware architectures and drivers, including network, USB, file system, memory management, and many others.

Technical explanation

How the issue affects the environment

The Linux kernel for GCP contained numerous security flaws across various subsystems such as ARM32, ARM64, MIPS, x86 architectures; multiple device drivers including Intel NPU, network drivers (Mellanox, Microsoft Azure Network Adapter), GPU and USB subsystems, Bluetooth, networking protocols (IPv4, IPv6, Netfilter, SCTP, L2TP), file systems (Ext4, FUSE, SMB), memory management, and kernel subsystems like signal handling and KVM virtualization. These vulnerabilities could be exploited by attackers to compromise systems running the vulnerable Linux kernel versions. The update provided by Ubuntu addresses these issues by patching the affected kernel components.

Operational impact

Why teams should care

If unpatched, systems running the affected Linux kernel on GCP could be vulnerable to attacks leading to unauthorized access, data leakage, or system compromise. This could result in service disruptions, data breaches, and loss of customer trust, impacting business operations and compliance. Applying the update mitigates these risks.

Immediate action

Apply the Ubuntu-provided update to the linux-gcp packages as indicated. After updating, reboot the system to activate changes. Due to an ABI change, recompile and reinstall any third-party kernel modules to maintain system stability.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions6.8.0-1070.78

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Security issues were discovered in the Linux kernel for GCP systems.
  • Affected subsystems include multiple architectures and drivers as listed by Ubuntu.
  • The advisory lists CVE identifiers associated with these vulnerabilities.
  • The update for linux-image-gcp packages includes version 6.8.0-1070.78 which contains the fixes.
  • A reboot is needed after the update to apply changes.
  • ABI changes require recompilation of third party kernel modules.

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source