Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8761-2: Linux kernel (Azure FIPS) vulnerabilities

Multiple security flaws were found in the Linux kernel used by Ubuntu's Azure FIPS-enabled versions. These flaws could let attackers potentially compromise affected systems. Ubuntu has released updates that fix these vulnerabilities across many parts of the kernel, including various hardware architectures and subsystems. Users should update their systems and reboot to protect against these issues.

Published 18/9/2026, 8:47:18 amVerified 19/9/2026, 1:29:45 pmRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

Multiple security flaws were found in the Linux kernel used by Ubuntu's Azure FIPS-enabled versions. These flaws could let attackers potentially compromise affected systems. Ubuntu has released updates that fix these vulnerabilities across many parts of the kernel, including various hardware architectures and subsystems. Users should update their systems and reboot to protect against these issues.

Technical explanation

How the issue affects the environment

The Ubuntu security notice USN-8761-2 reports numerous vulnerabilities within the Linux kernel for Azure FIPS variants, affecting architectures such as ARM32, ARM64, PowerPC, and various kernel subsystems including networking, drivers (Bluetooth, GPU, hardware monitoring), file systems (NTFS3, SMB), memory management, tracing infrastructure (KProbes, io_uring), network protocols (IPv4, IPv6, Multipath TCP, TLS), and security frameworks like Linux Security Modules (LSM). These vulnerabilities allow potential system compromise by attackers exploiting flaws in diverse kernel components. The update provides patched kernel image versions that address these security issues. The update necessitates recompilation of third-party kernel modules due to ABI changes and requires users to reboot the system to apply all security fixes effectively.

Operational impact

Why teams should care

If these vulnerabilities are exploited, attackers could compromise the integrity, confidentiality, or availability of systems running Ubuntu with the Linux kernel Azure FIPS package. This poses risks to enterprise cloud environments, especially those requiring FIPS compliance, potentially leading to data breaches, operational disruptions, or failure to meet security standards. Prompt application of updates is critical to protecting infrastructure and maintaining trust with customers and stakeholders.

Immediate action

Upgrade the Linux kernel packages to versions 6.8.0-1067.75+fips1 or later. After upgrading, reboot the system to ensure all security fixes are active. Recompile and reinstall any third-party kernel modules due to the ABI changes introduced by this update.

Affected and fixed releases

Affected versionslinux-image-azure-fips prior to 6.8.0-1067.75+fips1
Fixed versionslinux-image-azure-fips 6.8.0-1067.75+fips1

Temporary risk reduction

The advisory does not specify any workarounds. Systems should be updated and rebooted to fully mitigate the vulnerabilities.

Evidence and validation checklist

  • Ubuntu Security Notice USN-8761-2 published on 2026-09-18
  • Official update to linux-image-azure-fips package to version 6.8.0-1067.75+fips1
  • Description of affected kernel subsystems and architectures
  • Instructions to reboot system post-update and recompile third-party kernel modules

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source