Back to vendor advisories
Ubuntu Security NoticesUSN-8666-2

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - File systems infrastructure; - Ext4 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; - TIPC protocol; (CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986, CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)

Not listedCVSS not listedNot listed severity
Scope

What the vendor says is affected

The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.

Next step

What the vendor recommends

This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - File systems infrastructure; - Ext4 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N.

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory

CVE-2020-24588View CVSS, KEV, EPSS, and threat contextCVE-2025-27558View CVSS, KEV, EPSS, and threat contextCVE-2021-47378View CVSS, KEV, EPSS, and threat contextCVE-2026-23392View CVSS, KEV, EPSS, and threat contextCVE-2026-31405View CVSS, KEV, EPSS, and threat contextCVE-2026-31414View CVSS, KEV, EPSS, and threat contextCVE-2026-31448View CVSS, KEV, EPSS, and threat contextCVE-2026-31657View CVSS, KEV, EPSS, and threat contextCVE-2026-31668View CVSS, KEV, EPSS, and threat contextCVE-2026-43071View CVSS, KEV, EPSS, and threat contextCVE-2026-43198View CVSS, KEV, EPSS, and threat contextCVE-2026-43493View CVSS, KEV, EPSS, and threat contextCVE-2026-43499View CVSS, KEV, EPSS, and threat contextCVE-2026-46266View CVSS, KEV, EPSS, and threat contextCVE-2026-46331View CVSS, KEV, EPSS, and threat contextCVE-2026-52914View CVSS, KEV, EPSS, and threat contextCVE-2026-52924View CVSS, KEV, EPSS, and threat contextCVE-2026-52931View CVSS, KEV, EPSS, and threat contextCVE-2026-52955View CVSS, KEV, EPSS, and threat contextCVE-2026-52958View CVSS, KEV, EPSS, and threat contextCVE-2026-52982View CVSS, KEV, EPSS, and threat contextCVE-2026-52986View CVSS, KEV, EPSS, and threat contextCVE-2026-52989View CVSS, KEV, EPSS, and threat contextCVE-2026-52993View CVSS, KEV, EPSS, and threat contextCVE-2026-52999View CVSS, KEV, EPSS, and threat contextCVE-2026-53002View CVSS, KEV, EPSS, and threat contextCVE-2026-53006View CVSS, KEV, EPSS, and threat contextCVE-2026-53045View CVSS, KEV, EPSS, and threat contextCVE-2026-53088View CVSS, KEV, EPSS, and threat contextCVE-2026-53176View CVSS, KEV, EPSS, and threat contextCVE-2026-53212View CVSS, KEV, EPSS, and threat contextCVE-2026-53228View CVSS, KEV, EPSS, and threat contextCVE-2026-53359View CVSS, KEV, EPSS, and threat context