Ubuntu 7183 Published by

Ubuntu issued a coordinated set of security notices, patching dozens of vulnerabilities across the Linux kernel and the Axios Node.js HTTP client. The kernel updates span Ubuntu 16.04 through 26.04 LTS and cover cloud, OEM, and specialized hardware variants including Oracle, AWS, Azure, Google Cloud, and NVIDIA Tegra distributions. Key fixes address WiFi mesh network packet injection, a logic flaw labeled Fragnesia that enables local privilege escalation and container escapes, and prototype pollution bugs in Axios that allow proxy restrictions to be bypassed.

[USN-8631-2] Linux kernel (Oracle) vulnerabilities
[USN-8637-1] Linux kernel (OEM) vulnerabilities
[USN-8630-2] Linux kernel vulnerabilities
[USN-8633-2] Linux kernel vulnerabilities
[USN-8631-3] Linux kernel (NVIDIA Tegra IGX) vulnerabilities
[USN-8529-2] Linux kernel vulnerabilities
[USN-8530-2] Linux kernel (HWE) vulnerabilities
[USN-8548-2] Linux kernel vulnerabilities
[USN-8638-1] Axios vulnerabilities




[USN-8631-2] Linux kernel (Oracle) vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8631-2
August 13, 2026

linux-oracle vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oracle: Linux kernel for Oracle Cloud systems

Details:

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
linux-image-5.15.0-1110-oracle 5.15.0-1110.116
linux-image-oracle-5.15 5.15.0.1110.106
linux-image-oracle-lts-22.04 5.15.0.1110.106

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8631-2
https://ubuntu.com/security/notices/USN-8631-1
CVE-2025-27558, CVE-2026-31414, CVE-2026-31448, CVE-2026-31705,
CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086,
CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225,
CVE-2026-53228, CVE-2026-53359

Package Information:
https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1110.116



[USN-8637-1] Linux kernel (OEM) vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8637-1
August 13, 2026

linux-oem-7.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oem-7.0: Linux kernel for OEM systems

Details:

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Thunderbolt and USB4 drivers;
- Network traffic control;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
(CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53146,
CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150,
CVE-2026-53151, CVE-2026-53175, CVE-2026-53176, CVE-2026-53186,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246,
CVE-2026-53247, CVE-2026-53260, CVE-2026-53359)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
linux-image-7.0.0-1010-oem 7.0.0-1010.10
linux-image-oem-26.04 7.0.0-1010.10
linux-image-oem-26.04a 7.0.0-1010.10
linux-image-oem-7.0 7.0.0-1010.10

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8637-1
CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53146,
CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150,
CVE-2026-53151, CVE-2026-53175, CVE-2026-53176, CVE-2026-53186,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246,
CVE-2026-53247, CVE-2026-53260, CVE-2026-53359

Package Information:
https://launchpad.net/ubuntu/+source/linux-oem-7.0/7.0.0-1010.10



[USN-8630-2] Linux kernel vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8630-2
August 13, 2026

linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia-tegra,
linux-oracle vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-lowlatency: Linux low latency kernel
- linux-nvidia-tegra: Linux kernel for NVIDIA Tegra systems
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-lowlatency-hwe-6.8: Linux low latency kernel

Details:

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infrastructure;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- B.A.T.M.A.N. meshing protocol;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
linux-image-6.8.0-1031-nvidia-tegra 6.8.0-1031.32
linux-image-6.8.0-1031-nvidia-tegra-rt 6.8.0-1031.32
linux-image-6.8.0-1059-oracle 6.8.0-1059.62
linux-image-6.8.0-1059-oracle-64k 6.8.0-1059.62
linux-image-6.8.0-137-lowlatency 6.8.0-137.137.1
linux-image-6.8.0-137-lowlatency-64k 6.8.0-137.137.1
linux-image-lowlatency 6.8.0-137.137.1
linux-image-lowlatency-6.8 6.8.0-137.137.1
linux-image-lowlatency-64k 6.8.0-137.137.1
linux-image-lowlatency-64k-6.8 6.8.0-137.137.1
linux-image-nvidia-tegra 6.8.0-1031.32
linux-image-nvidia-tegra-6.8 6.8.0-1031.32
linux-image-nvidia-tegra-rt 6.8.0-1031.32
linux-image-nvidia-tegra-rt-6.8 6.8.0-1031.32
linux-image-oracle-6.8 6.8.0-1059.62
linux-image-oracle-64k-6.8 6.8.0-1059.62
linux-image-oracle-64k-lts-24.04 6.8.0-1059.62
linux-image-oracle-lts-24.04 6.8.0-1059.62

Ubuntu 22.04 LTS
linux-image-6.8.0-137-lowlatency 6.8.0-137.137.1~22.04.1
linux-image-6.8.0-137-lowlatency-64k 6.8.0-137.137.1~22.04.1
linux-image-lowlatency-6.8 6.8.0-137.137.1~22.04.1
linux-image-lowlatency-64k-6.8 6.8.0-137.137.1~22.04.1
linux-image-lowlatency-64k-hwe-22.04 6.8.0-137.137.1~22.04.1
linux-image-lowlatency-hwe-22.04 6.8.0-137.137.1~22.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8630-2
https://ubuntu.com/security/notices/USN-8630-1
CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359

Package Information:
https://launchpad.net/ubuntu/+source/linux-lowlatency/6.8.0-137.137.1
https://launchpad.net/ubuntu/+source/linux-nvidia-tegra/6.8.0-1031.32
https://launchpad.net/ubuntu/+source/linux-oracle/6.8.0-1059.62

https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-6.8/6.8.0-137.137.1~22.04.1



[USN-8633-2] Linux kernel vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8633-2
August 13, 2026

linux-aws-hwe, linux-azure, linux-gcp, linux-hwe vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe: Linux hardware enablement (HWE) kernel

Details:

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- GPU drivers;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- STMicroelectronics network drivers;
- NVME drivers;
- Ext4 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405,
CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657,
CVE-2026-31668, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499,
CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
linux-image-4.15.0-1188-gcp 4.15.0-1188.205~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-1195-aws 4.15.0-1195.208~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-1205-azure 4.15.0-1205.220~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-254-generic 4.15.0-254.266~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-254-lowlatency 4.15.0-254.266~16.04.1
Available with Ubuntu Pro
linux-image-aws-hwe 4.15.0.1195.208~16.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1205.220~16.04.1
Available with Ubuntu Pro
linux-image-gcp 4.15.0.1188.205~16.04.1
Available with Ubuntu Pro
linux-image-generic-hwe-16.04 4.15.0.254.266~16.04.1
Available with Ubuntu Pro
linux-image-gke 4.15.0.1188.205~16.04.1
Available with Ubuntu Pro
linux-image-lowlatency-hwe-16.04 4.15.0.254.266~16.04.1
Available with Ubuntu Pro
linux-image-oem 4.15.0.254.266~16.04.1
Available with Ubuntu Pro
linux-image-virtual-hwe-16.04 4.15.0.254.266~16.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8633-2
https://ubuntu.com/security/notices/USN-8633-1
CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2025-27558,
CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649,
CVE-2026-31657, CVE-2026-31668, CVE-2026-43198, CVE-2026-43493,
CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924,
CVE-2026-52931, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986,
CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088,
CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359



[USN-8631-3] Linux kernel (NVIDIA Tegra IGX) vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8631-3
August 13, 2026

linux-nvidia-tegra-igx vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-nvidia-tegra-igx: Linux kernel for NVIDIA Tegra IGX systems

Details:

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
linux-image-5.15.0-1054-nvidia-tegra-igx 5.15.0-1054.54
linux-image-5.15.0-1054-nvidia-tegra-igx-rt 5.15.0-1054.54
linux-image-nvidia-tegra-igx 5.15.0.1054.56
linux-image-nvidia-tegra-igx-5.15 5.15.0.1054.56
linux-image-nvidia-tegra-igx-rt 5.15.0.1054.56
linux-image-nvidia-tegra-igx-rt-5.15 5.15.0.1054.56

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8631-3
https://ubuntu.com/security/notices/USN-8631-2
https://ubuntu.com/security/notices/USN-8631-1
CVE-2025-27558, CVE-2026-31414, CVE-2026-31448, CVE-2026-31705,
CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086,
CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225,
CVE-2026-53228, CVE-2026-53359

Package Information:
https://launchpad.net/ubuntu/+source/linux-nvidia-tegra-igx/5.15.0-1054.54



[USN-8529-2] Linux kernel vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8529-2
August 13, 2026

linux-azure, linux-gcp, linux-hwe, linux-oracle vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe: Linux hardware enablement (HWE) kernel
- linux-oracle: Linux kernel for Oracle Cloud systems

Details:

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- InfiniBand drivers;
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core library;
- DCCP (Datagram Congestion Control Protocol);
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- X.25 network layer;
(CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
linux-image-4.15.0-1156-oracle 4.15.0-1156.167~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-1188-gcp 4.15.0-1188.205~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-1205-azure 4.15.0-1205.220~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-253-generic 4.15.0-253.265~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-254-generic 4.15.0-254.266~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-254-lowlatency 4.15.0-254.266~16.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1205.220~16.04.1
Available with Ubuntu Pro
linux-image-gcp 4.15.0.1188.205~16.04.1
Available with Ubuntu Pro
linux-image-generic-hwe-16.04 4.15.0.254.266~16.04.1
Available with Ubuntu Pro
linux-image-gke 4.15.0.1188.205~16.04.1
Available with Ubuntu Pro
linux-image-lowlatency-hwe-16.04 4.15.0.254.266~16.04.1
Available with Ubuntu Pro
linux-image-oem 4.15.0.254.266~16.04.1
Available with Ubuntu Pro
linux-image-oracle 4.15.0.1156.167~16.04.1
Available with Ubuntu Pro
linux-image-virtual-hwe-16.04 4.15.0.254.266~16.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8529-2
https://ubuntu.com/security/notices/USN-8529-1
CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-43503, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119,
CVE-2026-46243



[USN-8530-2] Linux kernel (HWE) vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8530-2
August 13, 2026

linux-aws-hwe vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems

Details:

It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284)

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- InfiniBand drivers;
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core library;
- DCCP (Datagram Congestion Control Protocol);
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- X.25 network layer;
(CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
linux-image-4.15.0-1195-aws 4.15.0-1195.208~16.04.1
Available with Ubuntu Pro
linux-image-aws-hwe 4.15.0.1195.208~16.04.1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8530-2
https://ubuntu.com/security/notices/USN-8530-1
CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43284, CVE-2026-43383, CVE-2026-43407,
CVE-2026-43414, CVE-2026-43503, CVE-2026-45988, CVE-2026-46043,
CVE-2026-46119, CVE-2026-46243



[USN-8548-2] Linux kernel vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8548-2
August 13, 2026

linux, linux-aws, linux-kvm vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-kvm: Linux kernel for cloud environments

Details:

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- DCCP (Datagram Congestion Control Protocol);
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- X.25 network layer;
(CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643,
CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637,
CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46119, CVE-2026-46243)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
linux-image-4.4.0-1157-kvm 4.4.0-1157.168
Available with Ubuntu Pro
linux-image-4.4.0-1194-aws 4.4.0-1194.209
Available with Ubuntu Pro
linux-image-4.4.0-283-generic 4.4.0-283.317
Available with Ubuntu Pro
linux-image-4.4.0-283-lowlatency 4.4.0-283.317
Available with Ubuntu Pro
linux-image-aws 4.4.0.1194.198
Available with Ubuntu Pro
linux-image-generic 4.4.0.283.289
Available with Ubuntu Pro
linux-image-generic-lts-xenial 4.4.0.283.289
Available with Ubuntu Pro
linux-image-kvm 4.4.0.1157.154
Available with Ubuntu Pro
linux-image-lowlatency 4.4.0.283.289
Available with Ubuntu Pro
linux-image-lowlatency-lts-xenial 4.4.0.283.289
Available with Ubuntu Pro
linux-image-virtual 4.4.0.283.289
Available with Ubuntu Pro
linux-image-virtual-lts-xenial 4.4.0.283.289
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-8548-2
https://ubuntu.com/security/notices/USN-8548-1
CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643,
CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637,
CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-43503, CVE-2026-45988, CVE-2026-46119, CVE-2026-46243



[USN-8638-1] Axios vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8638-1
August 13, 2026

node-axios vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Axios.

Software Description:
- node-axios: Promise based HTTP client for the browser and node.js

Details:

Ameer Assadi discovered that Axios did not properly handle certain
hostnames when applying NO_PROXY rules. An attacker could possibly use
this issue to bypass proxy restrictions and access internal services,
resulting in server-side request forgery. (CVE-2025-62718)

It was discovered that Axios did not properly protect certain HTTP
header values from prototype pollution. An attacker could possibly use
this issue to inject malicious values into outbound requests, resulting
in HTTP header injection. (CVE-2026-40175)

Sachin Patil and Amol Patil discovered that Axios did not properly apply
NO_PROXY rules to certain loopback addresses. An attacker could possibly
use this issue to bypass proxy restrictions and access internal
services, resulting in server-side request forgery. (CVE-2026-42043)

Yu Bao discovered that Axios did not properly protect JSON response
processing from prototype pollution. An attacker could possibly use this
issue to modify values in application responses, resulting in
authorization bypass or privilege escalation. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-42044)

It was discovered that Axios did not properly protect certain request
configuration options from prototype pollution. An attacker could
possibly use this issue to modify outbound HTTP requests, resulting in
security restrictions being bypassed. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-42264)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
node-axios 1.13.2+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 24.04 LTS
node-axios 1.6.8+dfsg-2ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 22.04 LTS
node-axios 0.26.0+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
node-axios 0.19.0+dfsg-2ubuntu0.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8638-1
CVE-2025-62718, CVE-2026-40175, CVE-2026-42043, CVE-2026-42044,
CVE-2026-42264