Ubuntu 7053 Published by

Ubuntu released two security notices addressing flaws within FRRouting software and Linux kernels designed for Azure systems. The FRR vulnerability could allow remote attackers to gain unauthorized access, so users must update their packages across various supported releases immediately. While the first fix applies via standard updates without a reboot, the kernel updates require restarting the computer after installation is complete. Older versions like 14.04 LTS might also face ABI changes that force administrators to recompile third party modules manually if they did not install standard metapackages.

[USN-8175-1] FRR vulnerability
[USN-8145-5] Linux kernel (Azure) vulnerabilities




[USN-8175-1] FRR vulnerability


==========================================================================
Ubuntu Security Notice USN-8175-1
April 15, 2026

frr vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

FRR could allow unintended access to network services.

Software Description:
- frr: FRRouting suite of internet protocols

Details:

It was discovered that FRR did not correctly handle certain network
requests. A remote attacker could possibly use this issue to gain
unauthorized access to resources.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
frr 10.4.1-3ubuntu1.2

Ubuntu 24.04 LTS
frr 8.4.4-1.1ubuntu6.6

Ubuntu 22.04 LTS
frr 8.1-1ubuntu1.15

Ubuntu 20.04 LTS
frr 7.2.1-1ubuntu0.2+esm4
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8175-1
CVE-2026-5107

Package Information:
https://launchpad.net/ubuntu/+source/frr/10.4.1-3ubuntu1.2
https://launchpad.net/ubuntu/+source/frr/8.4.4-1.1ubuntu6.6
https://launchpad.net/ubuntu/+source/frr/8.1-1ubuntu1.15



[USN-8145-5] Linux kernel (Azure) vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8145-5
April 15, 2026

linux-azure, linux-azure-4.15 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems

Details:

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- Cryptographic API;
- UDF file system;
- NFC subsystem;
- Network traffic control;
(CVE-2024-46777, CVE-2025-21735, CVE-2025-37849, CVE-2026-23060,
CVE-2026-23074)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS
linux-image-4.15.0-1199-azure 4.15.0-1199.214
Available with Ubuntu Pro
linux-image-azure-4.15 4.15.0.1199.167
Available with Ubuntu Pro
linux-image-azure-lts-18.04 4.15.0.1199.167
Available with Ubuntu Pro

Ubuntu 14.04 LTS
linux-image-4.15.0-1199-azure 4.15.0-1199.214~14.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1199.214~14.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8145-5
https://ubuntu.com/security/notices/USN-8145-4
https://ubuntu.com/security/notices/USN-8145-3
https://ubuntu.com/security/notices/USN-8145-2
https://ubuntu.com/security/notices/USN-8145-1
CVE-2024-46777, CVE-2025-21735, CVE-2025-37849, CVE-2026-23060,
CVE-2026-23074