Ubuntu Ships Another IBM Cloud Kernel Rollup Naming Hundreds of New Linux Flaws
This is an update to VTA-2026-000270, published on 12 September 2026, which covered the ongoing stream of Ubuntu Linux kernel security updates. That advisory could not name 348 of the CVEs now carried by Ubuntu Security Notice USN-8906-1, released on 8 October 2026, and the affected package set has shifted. The new notice applies specifically to linux-ibm-6.8, the kernel flavour Canonical builds for IBM cloud systems, on Ubuntu 22.04 LTS (jammy). Fixed builds are linux-image-6.8.0-1066-ibm and the linux-image-ibm-6.8 metapackage at version 6.8.0-1066.67~22.04.1. Organisations running 22.04 LTS workloads on IBM cloud infrastructure are in scope; other kernel flavours are addressed by separate notices.
The only flaw described individually in the notice is CVE-2025-10263, a hardware-level issue in some Arm processors. On affected silicon, a broadcast translation lookaside buffer (TLB) invalidation can complete before memory writes made through the invalidated translation have been globally observed. A local attacker could use that window to write to memory after permission to do so was revoked, bypassing memory protections or escalating privileges. For the remaining CVEs, Canonical has not published per-flaw exploitation details and instead lists the corrected subsystems, which span ARM64, ARM32, MIPS, PowerPC and x86 architecture code, GPU and HID drivers, Bluetooth, InfiniBand, SCSI, the ext4, FUSE, NTFS3 and SMB file systems, io_uring, memory management, netfilter, IPv4 and IPv6 networking, MPTCP, SCTP, TLS, wireless and MAC80211, key management, the LSM framework, ALSA and the KVM subsystem. The breadth of that list is typical of a cumulative kernel rollup rather than a single targeted defect, and most such issues are reachable only from a local account or a privileged guest context. The update also carries an unavoidable kernel ABI change, which is why the build number moved and why previously compiled third-party modules will no longer match the running kernel.
For a cloud-hosted fleet, the practical exposure is lateral: a tenant, a container breakout, or any foothold that yields unprivileged local code execution becomes the launch point for kernel-level privilege escalation, and a kernel compromise defeats every control running above it, including auditing and host-based detection. The CVE-2025-10263 behaviour is particularly awkward because it originates in processor behaviour rather than kernel logic alone, meaning the kernel change is a software mitigation for a hardware weakness. On current exploitation status, the evidence is thin and should be read plainly: FIRST EPSS puts CVE-2025-10263 at a 0.5% probability of exploitation within the next 30 days, CVE-2026-64524 and CVE-2026-64239 at 0.1%, and CVE-2026-92502, CVE-2026-64528, CVE-2026-64527, CVE-2026-64525, CVE-2026-64518, CVE-2026-64243, CVE-2026-64242, CVE-2026-64240 and CVE-2026-64237 each at 0.2%. None of the CVEs in this notice carry confirmed in-the-wild exploitation or a Known Exploited Vulnerabilities listing in the evidence available to us, and no public exploit campaign has been associated with them. The operational friction here is the ABI change rather than attacker pressure: fleets that rely on out-of-tree modules such as storage, networking or monitoring drivers will find those modules unloadable against the new kernel until rebuilt, and that is the factor most likely to delay deployment across an IBM cloud estate. Unpatched hosts remain exposed to a large set of local escalation and denial-of-service paths for as long as that delay persists, which matters most on multi-tenant or shared-administration systems where untrusted local code is a realistic starting position.
Attack Surface
Server OS, Cloud Service, Infrastructure
Tactics
Privilege Escalation, Defense Evasion, Impact
Techniques
- T1068 – Exploitation for Privilege Escalation
- T1211 – Exploitation for Defense Evasion
- T1499 – Endpoint Denial of Service
SuperPRO's Threat Countermeasures Procedures
- Upgrade Ubuntu 22.04 LTS (jammy) IBM cloud systems to linux-image-6.8.0-1066-ibm and linux-image-ibm-6.8 version 6.8.0-1066.67~22.04.1, then reboot, as the running kernel is not replaced until restart.
- Inventory hosts still on an older linux-ibm-6.8 ABI by comparing 'uname -r' against 6.8.0-1066-ibm, and treat any host reporting an earlier 6.8.0-10xx-ibm build as outstanding for CVE-2025-10263 and the remaining 348 CVEs in USN-8906-1.
- Rebuild and reinstall all third-party and DKMS kernel modules before the maintenance window closes, because USN-8906-1 introduces an unavoidable ABI change; run 'dkms status' and 'sudo dkms autoinstall -k 6.8.0-1066-ibm' to confirm every out-of-tree module compiles against the new kernel.
- Confirm the standard kernel metapackage linux-image-ibm-6.8 is still installed on each instance, since hosts where it was manually removed will not pick up 6.8.0-1066.67~22.04.1 through a routine apt upgrade and will silently stay on the vulnerable build.
- Reduce local attack surface on shared or multi-tenant IBM cloud instances by blacklisting kernel modules for subsystems named in this notice that the workload does not use, for example adding 'install nfc /bin/true', 'install rds /bin/true', 'install l2tp_ppp /bin/true' and 'install phonet /bin/true' to /etc/modprobe.d/usn-8906-hardening.conf.
- Restrict unprivileged access to kernel escalation primitives by setting kernel.unprivileged_userns_clone=0 and kernel.dmesg_restrict=1 via /etc/sysctl.d/ on hosts that do not require rootless containers, limiting the practical reach of local-only flaws until all instances carry 6.8.0-1066.67~22.04.1.
- Maintain Ubuntu Pro coverage on 22.04 LTS estates so that linux-ibm-6.8 kernel notices such as USN-8906-1 continue to be delivered through the esm-infra channel, and verify enrolment with 'pro status' on each IBM cloud instance.