USN-8886-1: Linux kernel (NVIDIA Tegra) vulnerabilities

Publication date

6 October 2026

Overview

Several security issues were fixed in the Linux kernel.

Releases


Packages

Details

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • NVDIMM (Non-Volatile Memory Device) drivers;
  • Handshake API;
  • ARM32 architecture;
  • ARM64 architecture;
  • MIPS architecture;
  • OpenRISC architecture;
  • PowerPC architecture;
  • S390 architecture;
  • x86 architecture;
  • Block layer subsystem;
  • Cryptographic API;
  • Intel NPU Driver;
  • Android drivers;
  • Rados block device (RBD) driver;
  • Bluetooth drivers;
  • Hardware random number generator core;
  • TPM device driver;
  • CPU frequency scaling framework;
  • Hardware crypto device drivers;
  • DMA engine subsystem;
  • FireWire subsystem;
  • Arm Firmware Framework for ARMv8-A(FFA);
  • GPIO subsystem;
  • GPU drivers;
  • HID...

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • NVDIMM (Non-Volatile Memory Device) drivers;
  • Handshake API;
  • ARM32 architecture;
  • ARM64 architecture;
  • MIPS architecture;
  • OpenRISC architecture;
  • PowerPC architecture;
  • S390 architecture;
  • x86 architecture;
  • Block layer subsystem;
  • Cryptographic API;
  • Intel NPU Driver;
  • Android drivers;
  • Rados block device (RBD) driver;
  • Bluetooth drivers;
  • Hardware random number generator core;
  • TPM device driver;
  • CPU frequency scaling framework;
  • Hardware crypto device drivers;
  • DMA engine subsystem;
  • FireWire subsystem;
  • Arm Firmware Framework for ARMv8-A(FFA);
  • GPIO subsystem;
  • GPU drivers;
  • HID subsystem;
  • Hardware monitoring drivers;
  • CoreSight HW tracing drivers;
  • I2C subsystem;
  • IIO ADC drivers;
  • IIO subsystem;
  • InfiniBand drivers;
  • Input Device core drivers;
  • Input Device (Mouse) drivers;
  • IOMMU subsystem;
  • Multiple devices driver;
  • Media drivers;
  • Multifunction device drivers;
  • Fastrpc Driver;
  • Amazon Nitro Secure Module driver;
  • MMC subsystem;
  • MTD block device drivers;
  • Ethernet bonding driver;
  • Network drivers;
  • Mellanox network drivers;
  • Texas Instruments network drivers;
  • NTB driver;
  • NVME drivers;
  • NVMEM (Non Volatile Memory) drivers;
  • Parport drivers;
  • Pin controllers subsystem;
  • x86 platform drivers;
  • i.MX PM domains;
  • System reset/shutdown drivers;
  • PTP clock framework;
  • Voltage and Current Regulator drivers;
  • S/390 drivers;
  • SCSI subsystem;
  • SPI subsystem;
  • Realtek RTL8723BS SDIO drivers;
  • VME bus staging drivers;
  • Thermal drivers;
  • Thunderbolt and USB4 drivers;
  • TTY drivers;
  • DesignWare USB2 driver;
  • USB Gadget drivers;
  • USB Host Controller drivers;
  • USB Dual Role (OTG-ready) Controller drivers;
  • USB Serial drivers;
  • USB Type-C Port Controller Manager driver;
  • vDPA drivers;
  • Virtio Host (VHOST) subsystem;
  • Framebuffer layer;
  • Watchdog drivers;
  • 9P distributed file system;
  • AFS file system;
  • File systems infrastructure;
  • BTRFS file system;
  • Ceph distributed file system;
  • EROFS file system;
  • exFAT file system;
  • F2FS file system;
  • FUSE (File system in Userspace);
  • Journaling layer for block devices (JBD2);
  • Network file system (NFS) client;
  • Network file system (NFS) server daemon;
  • NTFS3 file system;
  • OCFS2 file system;
  • Proc file system;
  • SMB network file system;
  • Tracing file system;
  • UDF file system;
  • XFS file system;
  • Key management;
  • BPF subsystem;
  • Control group (cgroup);
  • Glob pattern matching library;
  • MAC80211 subsystem;
  • Mellanox drivers;
  • Networking core;
  • Network sockets;
  • IPv6 networking;
  • Bluetooth subsystem;
  • Wireless networking;
  • IPv4 networking;
  • Netfilter;
  • Network traffic control;
  • SCTP protocol;
  • TCP network protocol;
  • XFRM subsystem;
  • RDMA verbs API;
  • io_uring subsystem;
  • IPC subsystem;
  • Audit subsystem;
  • Kernel CPU control infrastructure;
  • Perf events;
  • Kernel exit() syscall;
  • Kernel fork() syscall;
  • Scheduler infrastructure;
  • Signal handling mechanism;
  • Timer subsystem;
  • Tracing infrastructure;
  • Resizable hashtable library;
  • Memory management;
  • 6LoWPAN network protocol;
  • Asynchronous Transfer Mode (ATM) subsystem;
  • B.A.T.M.A.N. meshing protocol;
  • Ethernet bridge;
  • CAN network layer;
  • Ceph Core library;
  • Ethtool driver;
  • HSR network protocol;
  • IEEE802154.4 network protocol;
  • IUCV driver;
  • KCM (Kernel Connection Multiplexor) sockets driver;
  • IEEE 802.15.4 subsystem;
  • Multipath TCP;
  • Open vSwitch;
  • Packet sockets;
  • Phonet protocol;
  • Qualcomm IPC Router (QRTR);
  • RDS protocol;
  • RxRPC session sockets;
  • SMC sockets;
  • Sun RPC protocol;
  • TIPC protocol;
  • TLS protocol;
  • Unix domain sockets;
  • VMware vSockets driver;
  • X.25 network layer;
  • eXpress Data Path;
  • AppArmor security module;
  • Integrity Measurement Architecture(IMA) framework;
  • SELinux security module;
  • ALSA framework;
  • HD-audio driver;
  • QCOM ASoC drivers;
  • Simple audio multiplexer codec driver;
  • Texas InstrumentS Audio (ASoC/HDA) drivers;
  • SoC Audio for Freescale CPUs drivers;
  • Amlogic Meson SoC drivers;
  • SOF drivers;
  • NVIDIA Tegra ASoC drivers;
  • USB sound devices;
  • Perf tools;
  • KVM subsystem


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.

The problem can be corrected by updating your system to the following package versions:


Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

References



Have additional questions?

Talk to a member of the team ›