Home / mailings [USN-8729-1] Linux kernel vulnerabilities
Posted on 07 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8729-1
September 07, 2026
linux, linux-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop,
linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-raspi,
linux-realtime, linux-realtime-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-fips: Linux kernel with FIPS
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-gkeop: Linux kernel for Google Container Engine (GKE) systems
- linux-nvidia: Linux kernel for NVIDIA systems
- linux-nvidia-lowlatency: Linux low latency kernel for NVIDIA systems
- linux-raspi: Linux kernel for Raspberry Pi systems
- linux-realtime: Linux kernel for Real-time systems
- linux-nvidia-6.8: Linux kernel for NVIDIA systems
- linux-realtime-6.8: Linux kernel for Real-time systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055,
CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096,
CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103,
CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126,
CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134,
CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138,
CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180,
CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64518)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-1049-gkeop 6.8.0-1049.53
linux-image-6.8.0-1062-gke 6.8.0-1062.70
linux-image-6.8.0-1062-gke-64k 6.8.0-1062.70
linux-image-6.8.0-1062-nvidia 6.8.0-1062.65
linux-image-6.8.0-1062-nvidia-64k 6.8.0-1062.65
linux-image-6.8.0-1062-nvidia-lowlatency 6.8.0-1062.65.1
linux-image-6.8.0-1062-nvidia-lowlatency-64k 6.8.0-1062.65.1
linux-image-6.8.0-1064-raspi 6.8.0-1064.68
linux-image-6.8.0-1067-gcp 6.8.0-1067.75
linux-image-6.8.0-1067-gcp-64k 6.8.0-1067.75
linux-image-6.8.0-1067-gcp-fips 6.8.0-1067.75+fips1
Available with Ubuntu Pro
linux-image-6.8.0-139-fips 6.8.0-139.139+fips1
Available with Ubuntu Pro
linux-image-6.8.0-139-generic 6.8.0-139.139
linux-image-6.8.0-139-generic-64k 6.8.0-139.139
linux-image-6.8.1-1059-realtime 6.8.1-1059.60
Available with Ubuntu Pro
linux-image-fips 6.8.0-139.139+fips1
Available with Ubuntu Pro
linux-image-fips-6.8 6.8.0-139.139+fips1
Available with Ubuntu Pro
linux-image-gcp-6.8 6.8.0-1067.75
linux-image-gcp-64k-6.8 6.8.0-1067.75
linux-image-gcp-64k-lts-24.04 6.8.0-1067.75
linux-image-gcp-fips 6.8.0-1067.75+fips1
Available with Ubuntu Pro
linux-image-gcp-fips-6.8 6.8.0-1067.75+fips1
Available with Ubuntu Pro
linux-image-gcp-lts-24.04 6.8.0-1067.75
linux-image-generic 6.8.0-139.139
linux-image-generic-6.8 6.8.0-139.139
linux-image-generic-64k 6.8.0-139.139
linux-image-generic-64k-6.8 6.8.0-139.139
linux-image-generic-lpae 6.8.0-139.139
linux-image-gke 6.8.0-1062.70
linux-image-gke-6.8 6.8.0-1062.70
linux-image-gke-64k 6.8.0-1062.70
linux-image-gke-64k-6.8 6.8.0-1062.70
linux-image-gkeop 6.8.0-1049.53
linux-image-gkeop-6.8 6.8.0-1049.53
linux-image-intel-iot-realtime 6.8.1-1059.60
Available with Ubuntu Pro
linux-image-intel-iotg 6.8.0-139.139
linux-image-kvm 6.8.0-139.139
linux-image-laptop-23.10 6.8.0-139.139
linux-image-nvidia 6.8.0-1062.65
linux-image-nvidia-6.8 6.8.0-1062.65
linux-image-nvidia-64k 6.8.0-1062.65
linux-image-nvidia-64k-6.8 6.8.0-1062.65
linux-image-nvidia-lowlatency 6.8.0-1062.65.1
linux-image-nvidia-lowlatency-6.8 6.8.0-1062.65.1
linux-image-nvidia-lowlatency-64k 6.8.0-1062.65.1
linux-image-nvidia-lowlatency-64k-6.8 6.8.0-1062.65.1
linux-image-raspi 6.8.0-1064.68
linux-image-raspi-6.8 6.8.0-1064.68
linux-image-realtime 6.8.1-1059.60
Available with Ubuntu Pro
linux-image-realtime-6.8.1 6.8.1-1059.60
Available with Ubuntu Pro
linux-image-virtual 6.8.0-139.139
linux-image-virtual-6.8 6.8.0-139.139
Ubuntu 22.04 LTS
linux-image-6.8.0-1062-nvidia 6.8.0-1062.65~22.04.1
linux-image-6.8.0-1062-nvidia-64k 6.8.0-1062.65~22.04.1
linux-image-6.8.1-1059-realtime 6.8.1-1059.60~22.04.1
Available with Ubuntu Pro
linux-image-nvidia-6.8 6.8.0-1062.65~22.04.1
linux-image-nvidia-64k-6.8 6.8.0-1062.65~22.04.1
linux-image-nvidia-64k-hwe-22.04 6.8.0-1062.65~22.04.1
linux-image-nvidia-hwe-22.04 6.8.0-1062.65~22.04.1
linux-image-realtime-6.8.1 6.8.1-1059.60~22.04.1
Available with Ubuntu Pro
linux-image-realtime-hwe-22.04 6.8.1-1059.60~22.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-8729-1
CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055,
CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096,
CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103,
CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126,
CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134,
CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138,
CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180,
CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64518
Package Information:
https://launchpad.net/ubuntu/+source/linux/6.8.0-139.139
https://launchpad.net/ubuntu/+source/linux-fips/6.8.0-139.139+fips1
https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1067.75
https://launchpad.net/ubuntu/+source/linux-gcp-fips/6.8.0-1067.75+fips1
https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1062.70
https://launchpad.net/ubuntu/+source/linux-gkeop/6.8.0-1049.53
https://launchpad.net/ubuntu/+source/linux-nvidia/6.8.0-1062.65
https://launchpad.net/ubuntu/+source/linux-nvidia-lowlatency/6.8.0-1062.65.1
https://launchpad.net/ubuntu/+source/linux-raspi/6.8.0-1064.68
https://launchpad.net/ubuntu/+source/linux-realtime/6.8.1-1059.60
https://launchpad.net/ubuntu/+source/linux-nvidia-6.8/6.8.0-1062.65~22.04.1
https://launchpad.net/ubuntu/+source/linux-realtime-6.8/6.8.1-1059.60~22.04.1
--=-=-=Content-Type: application/pgp-signature; name="signature.asc"
