Ubuntu Extends Kernel Security Fixes to AWS Instances After Twenty New Flaws Surface
This advisory is a follow-up to VTA-2026-000270, published on 12 September 2026, which covered Ubuntu's earlier round of Linux kernel fixes. The underlying patch cycle is the same, but the scope has now widened to the cloud: Ubuntu has published USN-8817-3 for the Amazon Web Services kernel flavours, covering the linux-aws and linux-aws-6.8 packages on Ubuntu 24.04 LTS (noble) and 22.04 LTS (jammy). The notice carries a batch of twenty kernel security issues, of which only CVE-2025-10263 is identified and described individually, the remainder being grouped by affected subsystem rather than named one by one. The fixed builds are 6.8.0-1065.68 on 24.04 LTS and 6.8.0-1065.68~22.04.1 on 22.04 LTS, and they apply to the standard and 64k page-size kernel images alike. Any organisation running Ubuntu EC2 instances on the AWS-tuned kernel rather than the generic one now falls inside the affected set.
Only one issue in the set is described in detail by the vendor. CVE-2025-10263 is a hardware-level weakness in certain Arm processors, where a broadcast translation lookaside buffer invalidation can complete before memory writes made through the invalidated translation have been observed globally. In practice that means a local attacker could still write to memory after permission to do so had already been revoked, which opens a path to bypassing memory protections or escalating privileges on the host. The remaining fixes are grouped by subsystem rather than individually explained, spanning the ARM64 architecture code, InfiniBand drivers, general network drivers, the TCM subsystem, the B.A.T.M.A.N. mesh protocol, the HSR network protocol, IPv4 and IPv6 networking, Netfilter and the RDS protocol. Beyond the statement that an attacker could use these flaws to compromise the system, no per-CVE exploitation details, attack chains or proof-of-concept code have been published alongside this notice. The update also carries an unavoidable ABI change, which is why the kernel has been given a new version number.
The significance here is reach rather than novelty. Ubuntu's AWS kernel images underpin a very large share of Linux workloads in the public cloud, and the affected subsystems are weighted heavily toward networking code paths that are reachable from workloads, containers and tenant traffic rather than from the console alone. The Arm TLB issue is particularly relevant to Graviton-based instance families, where a flaw that undermines memory permission revocation erodes one of the boundaries that separates an unprivileged process from the kernel. The ABI change means third-party kernel modules compiled against the previous build will not load after the new kernel is in place, so fleets that depend on out-of-tree drivers or agent modules face an operational step beyond the package upgrade itself, and instances that defer the reboot continue to run the vulnerable kernel even after the package is installed. On current exploitation status, the picture is quiet: FIRST EPSS places CVE-2025-10263 at a 0.5% probability of exploitation in the next 30 days, with CVE-2026-64091 at 0.6%, CVE-2026-64007, CVE-2026-64000, CVE-2026-63993, CVE-2026-63992 and CVE-2026-63984 at 0.5%, CVE-2026-63924 and CVE-2026-63922 at 0.7%, and CVE-2026-63994, CVE-2026-63912 and CVE-2026-63888 at 0.8%. None of the CVEs in this notice have been reported as exploited in the wild, and no public exploit has been tied to them. For a Malaysian SOC on shift tonight, this is scheduled maintenance work for the next change window rather than an incident response trigger, with the main residual risk sitting in long-lived instances that are rarely rebooted.
Attack Surface
Cloud Service, Server OS, Infrastructure
Tactics
Privilege Escalation, Defense Evasion, Impact
Techniques
- T1068 – Exploitation for Privilege Escalation
- T1211 – Exploitation for Defense Evasion
- T1499 – Endpoint Denial of Service
- T1547.006 – Boot or Logon Autostart Execution: Kernel Modules and Extensions
SuperPRO's Threat Countermeasures Procedures
- Upgrade Ubuntu 24.04 LTS AWS instances to linux-image-6.8.0-1065-aws, linux-image-6.8.0-1065-aws-64k, linux-image-aws-6.8, linux-image-aws-64k-6.8, linux-image-aws-lts-24.04 or linux-image-aws-64k-lts-24.04 at version 6.8.0-1065.68 per USN-8817-3.
- Upgrade Ubuntu 22.04 LTS AWS instances to linux-image-6.8.0-1065-aws, linux-image-6.8.0-1065-aws-64k, linux-image-aws, linux-image-aws-6.8, linux-image-aws-64k or linux-image-aws-64k-6.8 at version 6.8.0-1065.68~22.04.1.
- Reboot every patched instance and confirm activation with uname -r returning 6.8.0-1065-aws (or 6.8.0-1065-aws-64k); package installation alone leaves the vulnerable kernel running until reboot.
- Rebuild and reinstall all third-party or out-of-tree kernel modules before or immediately after the reboot, since USN-8817-3 carries an ABI change and modules compiled against 6.8.0-1064 and earlier will fail to load; verify with lsmod and dmesg for module load failures.
- Inventory Graviton and other Arm64 EC2 fleets specifically, as CVE-2025-10263 is an Arm processor TLB invalidation flaw affecting the ARM64 architecture code path, and prioritise those instances in the change window.
- Audit the running fleet against the fixed builds with apt-cache policy linux-image-aws-lts-24.04 and dpkg -l 'linux-image-*aws*', flagging any instance still carrying 6.8.0-1064 or earlier rather than 6.8.0-1065.68 or 6.8.0-1065.68~22.04.1.
- Rebuild the EC2 AMIs and launch templates used for autoscaling from the USN-8817-3 packages so that newly launched Ubuntu 24.04 and 22.04 instances start on linux-image-6.8.0-1065-aws or linux-image-6.8.0-1065-aws-64k instead of reintroducing the superseded kernel.