Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8889-1: Linux kernel (OEM) vulnerabilities

A set of security issues were found in the Linux kernel used on some systems. One specific problem involves certain AMD processors that do not correctly check memory access controls, which could let someone with high-level access in a virtualized environment exploit memory areas of secure virtual machines. Other vulnerabilities affect many parts of the Linux kernel, and attackers might use these issues to compromise affected systems. Updates have been released to address these issues on affected systems, such as Ubuntu OEM Linux kernels.

QCS published 7/10/2026, 8:51:53 am ISTVendor disclosure 6/10/2026, 9:16:18 pm ISTVerified 7/10/2026, 8:51:53 am ISTRevision 1

In plain language

What this advisory means

A set of security issues were found in the Linux kernel used on some systems. One specific problem involves certain AMD processors that do not correctly check memory access controls, which could let someone with high-level access in a virtualized environment exploit memory areas of secure virtual machines. Other vulnerabilities affect many parts of the Linux kernel, and attackers might use these issues to compromise affected systems. Updates have been released to address these issues on affected systems, such as Ubuntu OEM Linux kernels.

Technical explanation

How the issue affects the environment

The Linux kernel was found to contain multiple security flaws, including a critical issue (CVE-2023-20585) where some AMD processors fail to properly perform Reverse Map Table (RMP) checks during IOMMU accesses to host buffers. This can be exploited by a local attacker with hypervisor-level access to trigger out-of-bounds memory conditions, compromising the integrity of SEV-SNP guest memory in virtualized environments. Additional vulnerabilities span numerous kernel subsystems, architectures, drivers, and frameworks, potentially allowing attackers to compromise system integrity or confidentiality. The update addresses these flaws across a wide array of components including various CPU architectures (ARM64, ARM32, MIPS, PowerPC, RISC-V, S390, x86), device drivers (ACPI, Bluetooth, GPU, Network drivers, USB, and many others), subsystems (IOMMU, DMA engine, File systems, Networking, Security modules), and other kernel frameworks.

Operational impact

Why teams should care

Organizations using affected Linux kernel versions, especially in cloud or virtualized settings with AMD processors and SEV-SNP technology, risk exposure to attacks that can compromise guest memory security and overall system integrity. Untreated systems remain vulnerable to potential local attacker exploits, which can lead to data breaches or system control loss. Deploying the updated kernel versions is critical to maintaining system security and protecting sensitive data in affected environments.

Immediate action

Apply the Linux kernel update to version 7.0.0-1015.15 or later for OEM systems as provided by Ubuntu for the 26.04 LTS release. After the update, reboot the system to complete the installation. Third-party kernel modules may require recompilation due to ABI changes in the kernel update.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions7.0.0-1015.15 for linux-image-7.0.0-1015-oem and related packages on Ubuntu 26.04 LTS resolute

Temporary risk reduction

The official source does not specify any workaround for these vulnerabilities. Systems should be updated promptly to mitigate exposure.

Evidence and validation checklist

  • Vendor advisory from Ubuntu Security Notices USN-8889-1
  • Detailed description of CVE-2023-20585 and broad range of Linux kernel component fixes
  • Package version updates specifying fixed kernel packages
  • Instructions indicating need for system reboot and module recompilation

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source