Back to vendor advisories
Ubuntu Security NoticesUSN-8888-2

USN-8888-2: Linux kernel (Azure) vulnerabilities

Severity not listed 1 CVE Published Oct 8, 2026 at 12:50 PM UTC

Summary

It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585)

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:

- ARM64 architecture;

- NVDIMM (Non-Volatile Memory Device) drivers;

- Handshake API;

- ARM32 architecture;

- MIPS architecture;

- OpenRISC architecture;

- PowerPC architecture;

- RISC-V architecture;

- S390 architecture;

- x86 architecture;

- Cryptographic API;

- Compute Acceleration Framework;

- Intel NPU Driver;

- ACPI drivers;

- Android drivers;

- Serial ATA and Parallel ATA drivers;

- Drivers core;

- DRBD Distributed Replicated Block Device drivers;

- Rados block device (RBD) driver;

- Ublk userspace block driver;

- Bluetooth drivers;

- Cdrom driver;

- Character device driver;

- TPM device driver;

- Data acquisition framework and drivers;

- Hardware crypto device drivers;

- CXL (Compute Express Link) drivers;

- DAX dirext access to differentiated memory framework;

- DIBS (Direct Internal Buffer Sharing) drivers;

- Buffer Sharing and Synchronization framework;

- DMA engine subsystem;

- DPLL subsystem;

- EDAC drivers;

- FireWire subsystem;

- Arm Firmware Framework for ARMv8-A(FFA);

- ARM SCMI message protocol;

- Intel Stratix 10 firmware drivers;

- FPGA Framework;

- GPIB drivers;

- GPIO subsystem;

- GPU drivers;

- HID subsystem;

- Microsoft Hyper-V drivers;

- Hardware monitoring drivers;

- CoreSight HW tracing drivers;

- Intel Trace Hub HW tracing drivers;

- I2C subsystem;

- I3C subsystem;

- IIO subsystem;

- IIO ADC drivers;

- IIO Magnetometer sensors drivers;

- InfiniBand drivers;

- Input Device (Miscellaneous) drivers;

- IOMMU subsystem;

- IRQ chip drivers;

- LED subsystem;

- Mailbox framework;

- Multiple devices driver;

- Media drivers;

- MemoryStick subsystem;

- Multifunction device drivers;

- Intel Management Engine Interface driver;

- Amazon Nitro Secure Module driver;

- MMC subsystem;

- MTD block device drivers;

- Network drivers;

- Ethernet bonding driver;

- Mellanox network drivers;

- Microsoft Azure Network Adapter (MANA) driver;

- Texas Instruments network drivers;

- MediaTek network drivers;

- NTB driver;

- NVME drivers;

- Device tree and open firmware driver;

- Operating Performance Points (OPP) driver;

- PCI subsystem;

- Pin controllers subsystem;

- x86 platform drivers;

- i.MX PM domains;

- MediaTek PM domains;

- Power supply drivers;

- PTP clock framework;

- RapidIO drivers;

- Voltage and Current Regulator drivers;

- Remote Processor subsystem;

- MPAM driver;

- Reset controller framework;

- Real Time Clock drivers;

- S/390 drivers;

- SCSI subsystem;

- Xilinx SoC drivers;

- SoundWire subsystem;

- SPI subsystem;

- Media staging drivers;

- Media Oriented Systems Transport (MOST) driver;

- NVIDIA Tegra embedded controller (NVEC) staging driver;

- Realtek RTL8723BS SDIO drivers;

- TCM subsystem;

- TTY drivers;

- UFS subsystem;

- USB DSL drivers;

- USB core drivers;

- DesignWare USB3 driver;

- USB Gadget drivers;

- USB Host Controller drivers;

- USB Dual Role (OTG-ready) Controller drivers;

- USB Serial drivers;

- vDPA drivers;

- VFIO drivers;

- Virtio Host (VHOST) subsystem;

- Framebuffer layer;

- Virtio drivers;

- Watchdog drivers;

- Xen hypervisor drivers;

- 9P distributed file system;

- AFS file system;

- File systems infrastructure;

- BTRFS file system;

- Ceph distributed file system;

- Ext4 file system;

- F2FS file system;

- FUSE (File system in Userspace);

- Journaling layer for block devices (JBD2);

- Network file systems library;

- Network file system (NFS) client;

- Network file system (NFS) server daemon;

- NTFS3 file system;

- OCFS2 file system;

- OrangeFS file system;

- Overlay file system;

- Proc file system;

- SMB network file system;

- BPF subsystem;

- File system encryption (fscrypt);

- MAC80211 subsystem;

- IPv4 networking;

- Live Update Orchestrator (LUO);

- Mellanox drivers;

- Networking core;

- Sun RPC protocol;

- Memory Management;

- Media input infrastructure;

- IPv6 networking;

- Bluetooth subsystem;

- Wireless networking;

- IP tunnels definitions;

- Netfilter;

- Network traffic control;

- SCTP protocol;

- TCP network protocol;

- XFRM subsystem;

- RDMA verbs API;

- User-space API (UAPI);

- Audit subsystem;

- Control group (cgroup);

- Kernel CPU control infrastructure;

- Kernel exit() syscall;

- Kernel fork() syscall;

- Kexec HandOver (KHO);

- Locking primitives;

- Scheduler infrastructure;

- Signal handling mechanism;

- Timer subsystem;

- Tracing infrastructure;

- Codetag library;

- Resizable hashtable library;

- Memory management;

- 9P file system network protocol;

- Asynchronous Transfer Mode (ATM) subsystem;

- B.A.T.M.A.N. meshing protocol;

- Ethernet bridge;

- CAN network layer;

- Ceph Core library;

- HSR network protocol;

- IEEE802154.4 network protocol;

- IFE protocol;

- IUCV driver;

- KCM (Kernel Connection Multiplexor) sockets driver;

- Logical Link layer;

- IEEE 802.15.4 subsystem;

- MultiProtocol Label Switching driver;

- Multipath TCP;

- Open vSwitch;

- Packet sockets;

- Phonet protocol;

- Packet sampling (psample);

- Qualcomm IPC Router (QRTR);

- RDS protocol;

- RxRPC session sockets;

- SMC sockets;

- TIPC protocol;

- TLS protocol;

- X.25 network layer;

- AppArmor security module;

- Integrity Measurement Architecture(IMA) framework;

- Landlock security;

- SELinux security module;

- ALSA framework;

- HD-audio driver;

- AMD SoC Alsa drivers;

- Texas InstrumentS Audio (ASoC/HDA) drivers;

- SoC Audio for Freescale CPUs drivers;

- MediaTek ASoC drivers;

- Amlogic Meson SoC drivers;

- QCOM ASoC drivers;

- SoundWire (SDCA) ASoC drivers;

- SoC audio core drivers;

- SOF drivers;

- NVIDIA Tegra ASoC drivers;

- USB sound devices;

- Perf tools;

- KVM subsystem;

View 1150 CVE identifiers

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

This update corrects flaws in the following subsystems:

  • ARM64 architecture
  • NVDIMM (Non-Volatile Memory Device) drivers
  • Handshake API
  • ARM32 architecture
  • MIPS architecture
  • OpenRISC architecture
  • PowerPC architecture
  • RISC-V architecture
  • S390 architecture
  • x86 architecture
  • Cryptographic API
  • Compute Acceleration Framework
  • Intel NPU Driver
  • ACPI drivers
  • Android drivers
  • Serial ATA and Parallel ATA drivers
  • Drivers core
  • DRBD Distributed Replicated Block Device drivers
  • Rados block device (RBD) driver
  • Ublk userspace block driver
  • Bluetooth drivers
  • Cdrom driver
  • Character device driver
  • TPM device driver
  • Data acquisition framework and drivers
  • Hardware crypto device drivers
  • CXL (Compute Express Link) drivers
  • DAX dirext access

CVEs in this advisory 1

Updates

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.