Ubuntu Extends Kernel Fixes to AWS FIPS Images Covering Twenty Flaws Including Arm TLB Weakness
Ubuntu has issued USN-8817-2, which carries a body of Linux kernel corrections across to the FIPS-validated kernel built for Amazon Web Services instances, the linux-aws-fips package on Ubuntu 24.04 LTS Noble. The notice names CVE-2025-10263, CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007 and CVE-2026-64091. Twenty identifiers are tracked for this event in total, and the fixed build is kernel 6.8.0-1065.68+fips1, available through Ubuntu Pro FIPS Updates. Systems running the generic or NVIDIA-flavoured kernels are not the subject of this particular notice, which is specific to the AWS FIPS kernel flavour.
Only one of the twenty issues is described in any mechanical detail by the vendor. CVE-2025-10263 is a hardware-level weakness in certain Arm processors, where a broadcast translation lookaside buffer invalidation can complete before memory writes made through the now-invalidated translation have been observed globally. In practice that leaves a narrow window in which a local attacker can keep writing to memory after the permission to do so has already been withdrawn, which can be used to bypass memory protections or climb to higher privilege on the host. The remainder of the set is published only by affected subsystem rather than by individual mechanism, covering the ARM64 architecture, InfiniBand drivers, general network drivers, the TCM subsystem, the B.A.T.M.A.N. meshing protocol, the HSR network protocol, IPv4 and IPv6 networking, Netfilter and the RDS protocol. Ubuntu states broadly that an attacker could possibly use these flaws to compromise the system, but has not published exploitation details, proof-of-concept code or attack chains for them, so no specific attack path should be assumed beyond the Arm TLB issue.
The significance of this notice is the population it reaches. FIPS kernels are deployed precisely where cryptographic validation is a compliance requirement, which in practice means regulated workloads in banking, government and healthcare running on AWS instances, and those estates tend to patch on a slower, change-controlled cadence than general fleets. A large share of the fixed subsystems sit on the network path, and the Arm64 and ARM64-adjacent corrections are directly relevant to Graviton-based instance families, so a single unpatched image replicated across an auto-scaling group multiplies the exposed surface quickly. The update also carries an unavoidable ABI change, which means the kernel version string moves and any third-party kernel modules compiled against the previous build will no longer load until rebuilt, a known cause of deferred patching in exactly these environments. On the identifiers for which verified exploitation evidence exists, the picture is quiet rather than urgent: FIRST EPSS places CVE-2025-10263, CVE-2026-64007, CVE-2026-64000, CVE-2026-63993, CVE-2026-63992 and CVE-2026-63984 at a 0.5 percent probability of exploitation in the next thirty days, CVE-2026-64091 at 0.6 percent, CVE-2026-63924 and CVE-2026-63922 at 0.7 percent, and CVE-2026-63994, CVE-2026-63912 and CVE-2026-63888 at 0.8 percent, and none of those identifiers appears in CISA's Known Exploited Vulnerabilities catalogue. Ubuntu has published no exploitation details, proof-of-concept code or attack chains alongside the notice, so the practical risk is a post-access privilege escalation and memory-protection bypass path on long-lived, compliance-bound cloud hosts rather than a demonstrated remote compromise.
Attack Surface
Server OS, Cloud Service, Infrastructure
Tactics
Privilege Escalation, Defense Evasion, Impact
Techniques
- T1068 – Exploitation for Privilege Escalation
- T1211 – Exploitation for Defense Evasion
- T1499 – Endpoint Denial of Service
SuperPRO's Threat Countermeasures Procedures
- Upgrade Ubuntu 24.04 LTS Noble AWS FIPS hosts to linux-image-6.8.0-1065-aws-fips, linux-image-aws-fips and linux-image-aws-fips-6.8 at version 6.8.0-1065.68+fips1 from the Ubuntu Pro FIPS Updates stream, then reboot, since the running kernel is not replaced until restart.
- Confirm the fix is live after reboot with uname -r and dpkg -l | grep aws-fips, treating any host still reporting a kernel older than 6.8.0-1065 as unpatched against CVE-2025-10263 and the nineteen other CVEs in USN-8817-2.
- Rebuild and reinstall all third-party kernel modules before or immediately after the upgrade, because USN-8817-2 carries an unavoidable ABI change and the new version number will prevent previously compiled out-of-tree modules such as DKMS-built storage, VPN or agent drivers from loading.
- Verify that the metapackages linux-image-aws-fips or linux-image-aws-fips-6.8 are installed rather than a pinned linux-image-6.8.0-xxxx-aws-fips package, so that the FIPS kernel tracks future USN updates instead of remaining frozen on a specific build.
- Rebake the golden AMI used for AWS auto-scaling groups and launch templates with the 6.8.0-1065.68+fips1 kernel, then recycle running instances, since patching live hosts alone leaves newly scaled instances booting the vulnerable image.
- Prioritise Graviton and other Arm64 instance families in the rollout, as CVE-2025-10263 is an Arm broadcast TLB invalidation weakness permitting local writes after permission revocation, and ARM64 architecture is one of the subsystems corrected by this notice.
- Alert on kernel oops, panic or BUG entries in dmesg and journald referencing the subsystems fixed here – ib_core or InfiniBand drivers, target_core_mod for TCM, batman_adv, hsr, nf_tables or Netfilter, and rds – and on unexpected root shells spawned from low-privileged service accounts on unpatched FIPS instances.