Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8875-2: Linux kernel (NVIDIA) vulnerabilities

Multiple security flaws were discovered in the Linux kernel used in NVIDIA systems, including a specific weakness in the i.MX clock driver where improper memory handling could lead to system crashes. These issues could allow local attackers to disrupt system operations or potentially compromise systems running affected versions.

QCS published 11/10/2026, 12:02:07 pm ISTVendor disclosure 9/10/2026, 2:08:43 pm ISTVerified 11/10/2026, 12:02:07 pm ISTRevision 1

In plain language

What this advisory means

Multiple security flaws were discovered in the Linux kernel used in NVIDIA systems, including a specific weakness in the i.MX clock driver where improper memory handling could lead to system crashes. These issues could allow local attackers to disrupt system operations or potentially compromise systems running affected versions.

Technical explanation

How the issue affects the environment

The Linux kernel's i.MX clock driver failed to properly handle certain memory allocation failure conditions, resulting in a null pointer dereference vulnerability (CVE-2022-3114). This flaw enables a local attacker to cause a denial of service through system crashes. Additionally, numerous other security issues were identified across a wide range of kernel subsystems and architectures, impacting components such as user-space APIs, multiple CPU architectures (ARM32, ARM64, MIPS, PowerPC, RISC-V, x86), device drivers (including GPU, network, USB, storage, and Bluetooth drivers), filesystems, networking stacks, kernel infrastructure (locking, scheduling, signals), and various hardware interfaces and protocols. These vulnerabilities collectively could be exploited to compromise system security.

Operational impact

Why teams should care

The vulnerabilities present risks of system crashes leading to denial of service and potentially allow attackers to compromise confidentiality, integrity, or availability of affected systems. For businesses relying on NVIDIA Linux kernel deployments, these issues can disrupt services, cause unexpected downtime, and pose security risks to data and operations.

Immediate action

To address these vulnerabilities, users should update their systems to the specified fixed Linux kernel packages provided in Ubuntu Security Notice USN-8875-2 and then reboot the system to apply the changes. Recompilation and reinstallation of third-party kernel modules may be necessary due to ABI changes.

Affected and fixed releases

Affected versionsThe Ubuntu 22.04 LTS Linux kernel version 5.15.0-1112.nvidia and related packages prior to 5.15.0-1112.113
Fixed versionslinux-image-5.15.0-1112-nvidia 5.15.0-1112.113 and related updated packages as specified in Ubuntu Security Notice USN-8875-2

Temporary risk reduction

The official source does not specify any workaround; applying the updates per vendor instructions is recommended.

Evidence and validation checklist

  • Official Ubuntu Security Notice USN-8875-2 dated 9 October 2026
  • Package version updates for linux-image-5.15.0-1112-nvidia to 5.15.0-1112.113
  • Description of CVE-2022-3114 null pointer dereference in i.MX clock driver causing denial of service
  • Listing of affected kernel subsystems and architecture vulnerabilities fixed in the update

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source