USN-8817-2

Source
https://ubuntu.com/security/notices/USN-8817-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8817-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8817-2
Upstream
CVE (20)
Related
Published
2026-09-30T08:00:26Z
Modified
2026-09-30T18:27:45Z
Summary
linux-aws-fips vulnerabilities
Details

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263)

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:

  • ARM64 architecture;
  • InfiniBand drivers;
  • Network drivers;
  • TCM subsystem;
  • B.A.T.M.A.N. meshing protocol;
  • HSR network protocol;
  • IPv4 networking;
  • IPv6 networking;
  • Netfilter;
  • RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
References

Affected packages

Ubuntu:Pro:FIPS-updates:24.04:LTS / linux-aws-fips

Package

Name
linux-aws-fips
Purl
pkg:deb/ubuntu/linux-aws-fips?arch=source&distro=fips-updates%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.8.0-1065.68+fips1

Affected versions

6.*
6.8.0-1035.37+fips1
6.8.0-1036.38+fips1
6.8.0-1038.40+fips1
6.8.0-1039.41+fips1
6.8.0-1040.42+fips1
6.8.0-1041.43+fips1
6.8.0-1042.44+fips1
6.8.0-1043.45+fips1
6.8.0-1044.46+fips1
6.8.0-1045.47+fips1
6.8.0-1046.49+fips1
6.8.0-1047.50+fips1
6.8.0-1050.53+fips1
6.8.0-1051.54+fips1
6.8.0-1052.55+fips1
6.8.0-1053.56+fips1
6.8.0-1055.58+fips1
6.8.0-1057.60+fips1
6.8.0-1060.63+fips1
6.8.0-1061.64+fips1
6.8.0-1062.65+fips1
6.8.0-1063.66+fips1
6.8.0-1064.67+fips1

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "linux-aws-fips-cloud-tools-6.8.0-1065",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-aws-fips-headers-6.8.0-1065",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-aws-fips-tools-6.8.0-1065",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-buildinfo-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-cloud-tools-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-headers-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-image-unsigned-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-image-unsigned-hmac-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-modules-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-modules-extra-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        },
        {
            "binary_name":  "linux-tools-6.8.0-1065-aws-fips",
            "binary_version":  "6.8.0-1065.68+fips1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2025-10263",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "high",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-53131",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-53186",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "high",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-53216",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "low",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-53221",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-53354",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-53355",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63886",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63887",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63888",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63912",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63922",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63924",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63984",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63992",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63993",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-63994",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-64000",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-64007",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-64091",
            "severity":  [
                {
                    "score":  "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                    "type":  "CVSS_V4"
                },
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "high",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:Pro:FIPS-updates:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8817-2.json"