Ubuntu Extends Kernel Patch Wave to FIPS Certified Systems With Nineteen New CVEs
Ubuntu has published USN-8818-6, dated 2 October 2026, which carries an earlier round of kernel fixes across to the FIPS-certified kernel on Ubuntu 22.04 LTS (Jammy). The difference that matters for readers who already handled the generic-kernel notices in this series is scope and naming: this notice lists nineteen CVEs, among them CVE-2025-10263, CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007 and CVE-2026-64091. The affected packages are linux-image-5.15.0-194-fips, linux-image-fips and linux-image-fips-5.15, all of which are delivered through the FIPS Updates stream available with Ubuntu Pro. Systems running the standard generic kernel were addressed by the earlier notices in this series; this one is specifically for estates that chose the FIPS-140 certified build.
Only one flaw in the set comes with a described mechanism. CVE-2025-10263 concerns the behaviour of some Arm processors, which could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. In practice that creates a window where a local attacker can still write to memory after permission to do so has been revoked, which is the kind of primitive that undermines memory protection boundaries and can be chained toward privilege escalation. For the remaining issues, the vendor has not published exploitation details and has described them only by the subsystem in which the flaw was corrected: the ARM64 architecture, InfiniBand drivers, network drivers, the TCM subsystem, the exFAT file system, the NFS client and server daemon, the B.A.T.M.A.N. meshing protocol, IPv4 and IPv6 networking, Netfilter and the RDS protocol. The update also carries an unavoidable ABI change, so the fixed kernel ships under a new version number rather than as an in-place replacement of the existing one.
The strategic weight of this notice comes from where FIPS kernels are deployed. Organisations run the FIPS build because a regulator, a certification scheme or a customer contract requires validated cryptography, which means these hosts are disproportionately found in banking, government, defence and healthcare environments carrying sensitive workloads. Those same estates typically move more slowly than general-purpose fleets, because certified builds are tied to a subscription stream and because the ABI change forces third-party kernel modules to be recompiled and reinstalled before the new kernel is usable. The practical consequence is that a FIPS host can sit on a vulnerable kernel for longer than an equivalent generic host, with the exposure concentrated on subsystems that are reachable from the network — NFS, Netfilter, IPv4 and IPv6 stacks and network drivers among them — rather than confined to local-only code paths. On current exploitation status, the evidence is modest: FIRST EPSS places CVE-2025-10263 at a 0.5 percent probability of exploitation in the next 30 days, with CVE-2026-64091 at 0.4 percent, CVE-2026-64007, CVE-2026-63994, CVE-2026-63993 and CVE-2026-63992 each at 0.5 percent, CVE-2026-63924, CVE-2026-63922 and CVE-2026-63912 at 0.7 percent, and CVE-2026-63888 and CVE-2026-63887 at 0.8 percent. No confirmed in-the-wild exploitation has been reported against this set, and no public exploit code is referenced in the notice. This is a scheduled maintenance event with a known deadline rather than an incident in progress, but the privilege-escalation potential of a kernel memory-protection bypass on a compliance-critical host is not something an estate can carry indefinitely.
Attack Surface
Server OS, Endpoint OS, Infrastructure
Tactics
Privilege Escalation, Defense Evasion, Impact
Techniques
- T1068 – Exploitation for Privilege Escalation
- T1211 – Exploitation for Defense Evasion
- T1499 – Endpoint Denial of Service
SuperPRO's Threat Countermeasures Procedures
- Update Ubuntu 22.04 LTS (Jammy) FIPS hosts to linux-image-5.15.0-194-fips version 5.15.0-194.204+fips1, with the metapackages linux-image-fips and linux-image-fips-5.15 at 5.15.0.194.113, then reboot – the running kernel is not replaced until restart.
- Confirm the FIPS Updates stream is attached and enabled on each host before patching, as these packages ship only through Ubuntu Pro – verify with 'pro status' and enable the fips-updates service where it is not already active.
- Inventory and recompile all third-party kernel modules before the reboot window, since USN-8818-6 carries an unavoidable ABI change and the new kernel version will not load modules built against 5.15.0-193 or earlier.
- Verify remediation on each host with 'uname -r' expecting 5.15.0-194-fips, and with 'dpkg -l | grep linux-image-fips' to catch hosts where the metapackage was manually uninstalled and so will not pull the new kernel automatically.
- Prioritise Arm64 FIPS hosts in the patch schedule, as CVE-2025-10263 is the Arm processor TLB invalidation flaw that allows a local attacker to write to memory after permission has been revoked.
- Restrict local shell access on FIPS-certified hosts pending reboot – audit sudo group membership, disable unused interactive service accounts, and review SSH AllowUsers lists, since the named Arm flaw requires local access to exploit.
- Pending reboot, reduce exposure of the network-facing subsystems named in the notice by firewalling NFS (TCP/UDP 2049 and rpcbind on 111) to known client ranges and unloading unused modules such as rds and batman-adv via /etc/modprobe.d blacklist entries.