Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities

Ubuntu says several Linux kernel issues were fixed in the Raspberry Pi kernel packages. One of the issues, called Fragnesia, could let a local attacker gain higher privileges or possibly escape a container. The notice is dated 29 July 2026 and the listed fixes apply to Ubuntu 20.04 LTS and 18.04 LTS Raspberry Pi kernel packages.

Published 29/7/2026, 7:43:21 amVerified 30/7/2026, 9:18:10 amRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

Ubuntu says several Linux kernel issues were fixed in the Raspberry Pi kernel packages. One of the issues, called Fragnesia, could let a local attacker gain higher privileges or possibly escape a container. The notice is dated 29 July 2026 and the listed fixes apply to Ubuntu 20.04 LTS and 18.04 LTS Raspberry Pi kernel packages.

Technical explanation

How the issue affects the environment

USN-8615-2 addresses multiple Linux kernel vulnerabilities in Raspberry Pi builds. The notice identifies CVE-2026-43503 as a logic flaw in the XFRM ESP-in-TCP subsystem when handling socket buffer fragments, with potential local privilege escalation and possible container escape. The notice also states that additional kernel issues were fixed across several subsystems, including InfiniBand, STMicroelectronics network drivers, NVME, SCSI, USB over IP, NFS server, SMB, tracing, B.A.T.M.A.N., Ethernet bridge, Ceph, IPv4, IPv6, Netfilter, RxRPC, and X.25. The notice does not provide exploit details for each CVE beyond saying an attacker could possibly use them to compromise the system.

Operational impact

Why teams should care

Affected Raspberry Pi systems running the listed Ubuntu kernel packages may be exposed to local privilege escalation or other kernel-level compromise conditions. For environments using containers, the Fragnesia issue may also affect container isolation. The notice does not state whether exploitation in the wild is known.

Immediate action

Update the affected Raspberry Pi kernel packages to the versions listed in the notice, then reboot the system so the new kernel is loaded. Ubuntu also notes that the kernel update has an ABI change, so any third-party kernel modules must be recompiled and reinstalled.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsUbuntu 20.04 LTS focal: linux-image-5.4.0-1144-raspi 5.4.0-1144.157, Ubuntu 20.04 LTS focal: linux-image-raspi 5.4.0.1144.175, Ubuntu 20.04 LTS focal: linux-image-raspi-5.4 5.4.0.1144.175, Ubuntu 20.04 LTS focal: linux-image-raspi2 5.4.0.1144.175, Ubuntu 18.04 LTS bionic: linux-image-5.4.0-1144-raspi 5.4.0-1144.157~18.04.1, Ubuntu 18.04 LTS bionic: linux-image-raspi-5.4 5.4.0.1144.157~18.04.1, Ubuntu 18.04 LTS bionic: linux-image-raspi-hwe-18.04 5.4.0.1144.157~18.04.1

Temporary risk reduction

The official notice does not specify a workaround.

Evidence and validation checklist

  • Publication date in the notice: 29 July 2026.
  • Notice title: USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities.
  • Affected release families explicitly listed: Ubuntu 20.04 LTS and 18.04 LTS.
  • Packages listed: linux-raspi and linux-raspi-5.4.
  • Fixed package versions listed in the notice for each release.
  • The notice instructs users to reboot after a standard system update.
  • The notice warns of an unavoidable ABI change and says third-party kernel modules must be recompiled and reinstalled.
  • CVE-2026-43503 is described as a logic flaw in XFRM ESP-in-TCP handling socket buffer fragments.
  • The notice states the other CVEs affect multiple kernel subsystems, but does not provide per-CVE technical detail or exploitation status in the wild.

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
USN-8615-2: Linux kernel (Raspberry Pi) | Advisory | QCS