Ubuntu Patches Twenty Kernel Flaws Including An Arm TLB Invalidation Weakness
Canonical published security notice USN-8818-4 on 30 September 2026, covering twenty CVEs fixed in the Linux kernel packages shipped for Ubuntu 22.04 LTS (jammy). The notice applies to two package families: linux, the general-purpose kernel, and linux-nvidia, the kernel variant built for NVIDIA systems. The fixed builds are the 5.15.0-194.204 series for generic, generic-64k and generic-lpae images, and the 5.15.0-1111.112 series for the nvidia and nvidia-lowlatency images, with the corresponding metapackages moving to 5.15.0.194.171 and 5.15.0.1111.111 respectively. The CVEs addressed are CVE-2025-10263, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007 and CVE-2026-64091. This is the fourth notice in the USN-8818 series, following USN-8818-1, USN-8818-2 and USN-8818-3, and extends the same body of kernel fixes to the 22.04 LTS generic and NVIDIA kernels.
Only one of the twenty issues is described in technical terms in the notice itself. CVE-2025-10263 concerns certain Arm processors that could complete a broadcast translation lookaside buffer invalidation before memory writes made through the now-invalidated translation were globally observed by the rest of the system. The practical consequence is a window in which a local attacker could write to memory after permission to do so had already been revoked, which Canonical describes as a possible route to bypassing memory protections or escalating privileges. For the remaining nineteen CVEs, the vendor has not published exploitation details or per-CVE descriptions in this notice; it states only that an attacker could possibly use them to compromise the system and identifies the affected subsystems. Those subsystems are the ARM64 architecture code, InfiniBand drivers, network drivers, the TCM subsystem, the exFAT file system, the NFS client and the NFS server daemon, the B.A.T.M.A.N. meshing protocol, IPv4 and IPv6 networking, Netfilter and the RDS protocol.
The practical exposure here is broad but ordinary. Every Ubuntu 22.04 LTS host running a 5.15 generic, 64k, lpae, virtual or NVIDIA kernel older than the fixed builds carries all twenty issues, and because a kernel change only takes effect on reboot, machines that have taken the package update but not restarted are still running vulnerable code. Canonical also flags an unavoidable ABI change in this release, meaning any third-party or out-of-tree kernel modules built against the previous ABI will not load against the new kernel until they are rebuilt. On exploitation, the picture is calm rather than urgent: FIRST EPSS puts the probability of exploitation in the next thirty days at 0.5% for CVE-2025-10263, CVE-2026-64007, CVE-2026-63993, CVE-2026-63992 and CVE-2026-63984, 0.6% for CVE-2026-64091, 0.7% for CVE-2026-63924 and CVE-2026-63922, and 0.8% for CVE-2026-63994, CVE-2026-63912, CVE-2026-63888 and CVE-2026-63887. No exploitation data was available for the remaining CVEs in the notice, and that absence should be read as a gap in evidence rather than as assurance that they are harmless. None of these flaws is described as remotely exploitable without local access in the vendor's own text, and the Arm TLB issue in particular matters most on shared or multi-tenant arm64 hosts where an untrusted local user already has a foothold. Fleets running NFS servers, containerised workloads with exposed kernel networking paths, or NVIDIA compute nodes on jammy represent the largest concentration of affected systems.
Attack Surface
Endpoint OS, Server OS, Infrastructure
Tactics
Privilege Escalation, Defense Evasion, Impact
Techniques
- T1068 – Exploitation for Privilege Escalation
- T1211 – Exploitation for Defense Evasion
- T1499 – Endpoint Denial of Service
SuperPRO's Threat Countermeasures Procedures
- On Ubuntu 22.04 LTS (jammy) general-purpose hosts, update to linux-image-5.15.0-194-generic, linux-image-5.15.0-194-generic-64k or linux-image-5.15.0-194-generic-lpae at version 5.15.0-194.204, with metapackages linux-image-generic, linux-image-generic-64k, linux-image-generic-lpae and linux-image-virtual at 5.15.0.194.171. Multi-tenant and shared arm64 hosts should be taken in tonight's window; single-tenant servers can wait for the next scheduled maintenance window.
- On NVIDIA systems, update linux-image-5.15.0-1111-nvidia and linux-image-5.15.0-1111-nvidia-lowlatency to 5.15.0-1111.112 and the linux-image-nvidia and linux-image-nvidia-lowlatency metapackages to 5.15.0.1111.111, as these are shipped in the same notice but carry a separate version stream from the generic kernel.
- Reboot every patched host – the kernel fix in USN-8818-4 does not take effect until restart – and verify afterwards that uname -r reports 5.15.0-194-generic (or the matching 64k, lpae or 5.15.0-1111-nvidia flavour) rather than the previous build.
- Because USN-8818-4 carries an unavoidable kernel ABI change, rebuild and reinstall all third-party and out-of-tree kernel modules before or immediately after the reboot; run dkms status on each host to confirm every DKMS module has a build registered against 5.15.0-194 or 5.15.0-1111 and will load on the new kernel.
- Confirm the standard kernel metapackages (linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-generic-lpae, linux-image-nvidia) are still installed on each jammy host, since Canonical's automatic ABI transition depends on them; hosts pinned directly to a versioned linux-image-5.15.0-xxx package will not pick up the new kernel and must be updated by hand.
- Prioritise arm64 estate for CVE-2025-10263 specifically – the generic-64k and generic-lpae images and any Arm-based jammy nodes – as this is the one issue in the notice for which Canonical describes a concrete mechanism, a broadcast TLB invalidation completing before the associated memory writes are globally observed.
- For 22.04 LTS systems that need coverage beyond the standard support window, enrol them in Ubuntu Pro, which Canonical states provides ten-year security coverage for 25,000-plus packages across the Main and Universe repositories and is free for up to five machines.