USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities
Ubuntu issued a security update for the Azure FIPS Linux kernel on Ubuntu 22.04 LTS. The update addresses many kernel flaws. Specifically described risks include disclosure of kernel memory through a malicious NTFS image, local disclosure of sensitive processor data on some AMD CPUs, and possible local privilege escalation on some AMD Zen 2 CPUs.
Published 29/7/2026, 7:46:56 amVerified 29/7/2026, 7:54:33 pmRevision 1
In plain language
What this advisory means
Ubuntu issued a security update for the Azure FIPS Linux kernel on Ubuntu 22.04 LTS. The update addresses many kernel flaws. Specifically described risks include disclosure of kernel memory through a malicious NTFS image, local disclosure of sensitive processor data on some AMD CPUs, and possible local privilege escalation on some AMD Zen 2 CPUs.
Technical explanation
How the issue affects the environment
CVE-2023-45896 is an out-of-bounds read caused by inadequate NTFS filename-length validation; a crafted NTFS image can expose kernel memory after it is mounted and accessed. CVE-2025-54505 concerns data not being cleared from the floating-point divider during speculative execution on some AMD processors, allowing a local attacker to disclose sensitive information. CVE-2025-54518 concerns insufficient isolation of shared operation-cache resources on some AMD Zen 2 processors; a local attacker could possibly corrupt instructions running at higher privilege and escalate privileges. The notice also corrects a large set of additional vulnerabilities across kernel architectures, drivers, filesystems, memory management, virtualization, security, networking, cryptography, audio, and other subsystems, but does not provide individual technical descriptions for those issues in the supplied evidence.
Operational impact
Why teams should care
Successful exploitation could expose kernel or processor-resident sensitive information, permit local privilege escalation on affected AMD Zen 2 systems, or otherwise compromise an affected system through one of the additional corrected kernel flaws. Actual exposure depends on the hardware and kernel features in use.
Immediate action
Install the applicable FIPS Updates package version through a standard system update, then reboot to activate the updated kernel. These FIPS-140 certified packages with security fixes are available through Ubuntu Pro. Because the update includes an ABI change, recompile and reinstall any installed third-party kernel modules. A standard upgrade performs this automatically when the standard kernel metapackages remain installed.
Affected and fixed releases
Affected versionsUbuntu 22.04 LTS systems using the linux-azure-fips package family; the official notice does not provide a separate vulnerable-version range.
The official notice does not specify a workaround.
Evidence and validation checklist
Ubuntu USN-8620-2 was published on 29 July 2026.
The affected release listed by Ubuntu is 22.04 LTS.
The package identified by Ubuntu is linux-azure-fips.
Ubuntu states that a standard system update and reboot are required.
Ubuntu lists three corrected package versions for the Azure FIPS kernel.
Ubuntu warns that the ABI change may require third-party kernel modules to be recompiled and reinstalled.
The notice explicitly describes CVE-2023-45896, CVE-2025-54505, and CVE-2025-54518 and references a much larger CVE set for additional kernel subsystems.
Authoritative reference
Ubuntu Security Notices
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.