Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8645-1: Linux kernel (Oracle) vulnerabilities

Researchers found that the Linux kernel's WiFi code had a flaw making it possible for an attacker near your device to inject harmful data packets. This happened because a previous fix was incorrect. Beyond this, multiple security weaknesses were found in the Linux kernel that could let attackers compromise your system. Updates are available to fix these security problems in many areas of the kernel.

Published 18/8/2026, 6:23:33 pmVerified 18/8/2026, 7:24:42 pmRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

Researchers found that the Linux kernel's WiFi code had a flaw making it possible for an attacker near your device to inject harmful data packets. This happened because a previous fix was incorrect. Beyond this, multiple security weaknesses were found in the Linux kernel that could let attackers compromise your system. Updates are available to fix these security problems in many areas of the kernel.

Technical explanation

How the issue affects the environment

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef identified that the Linux kernel's WiFi implementation improperly handled aggregated frames within mesh networks due to an incorrect prior fix addressing CVE-2020-24588. This vulnerability (CVE-2025-27558) permits a physically proximate attacker to inject arbitrary packets into the network stack. Additionally, the Linux kernel contained multiple security flaws across various subsystems—including x86 architecture, Cryptographic API, various GPU and network drivers, multiple filesystems (Ext4, OCFS2), IPv4 and IPv6 networking stacks, TCP and multipath TCP protocols, locking primitives, meshing protocols (B.A.T.M.A.N.), and other protocols such as SCTP, SMC sockets, and TIPC—that could allow attackers to compromise system integrity or confidentiality if exploited. This security update addresses these vulnerabilities to mitigate the risk of system compromise.

Operational impact

Why teams should care

These vulnerabilities potentially allow attackers, particularly those physically near the affected devices, to execute unauthorized actions such as injecting network packets or compromising system security. Such compromises could lead to unauthorized data access, service disruption, or unauthorized control over the system. Organizations running affected Linux kernel versions on Ubuntu (Oracle Cloud systems) risk exposure to these attacks if they do not apply the available security updates promptly.

Immediate action

Apply the security updates provided by Ubuntu for the Linux kernel packages specific to your Ubuntu release and system architecture. After updating, reboot your system to ensure all patches take effect. Note that due to unavoidable changes in the kernel's Application Binary Interface (ABI), you must recompile and reinstall all third-party kernel modules after upgrading. Follow Ubuntu's official update instructions for detailed steps.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Description of CVE-2025-27558 showing WiFi aggregated frames flaw due to incorrect prior fix (CVE-2020-24588) allowing packet injection by nearby attacker.
  • Mention of multiple security issues in Linux kernel subsystems that could let attackers compromise the system.
  • List of subsystems affected including networking protocols, drivers, filesystems, cryptography, and locking primitives.
  • Recommendation to update Linux kernel packages and reboot system.
  • Notification about ABI changes requiring recompilation of third-party kernel modules.
  • No explicit indication of exploitation in the wild or available workarounds.

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source