Ubuntu Ships Fresh NVIDIA Kernel Fixes For Seventeen Newly Named Flaws
Our advisory VTA-2026-000270, published on 12 September 2026, already covered the ongoing round of Linux kernel fixes for Ubuntu NVIDIA systems. This follow-up exists because Ubuntu Security Notice USN-8842-1, published 29 September 2026, names seventeen CVEs that the earlier advisory could not list, among them CVE-2026-64091, CVE-2026-64007, CVE-2026-64000, CVE-2026-63994, CVE-2026-63993, CVE-2026-63992, CVE-2026-63984, CVE-2026-63924, CVE-2026-63922, CVE-2026-63912, CVE-2026-63888, CVE-2026-63887, CVE-2026-63886, CVE-2026-53355, CVE-2026-53221, CVE-2026-53186 and CVE-2026-53131, alongside CVE-2026-53216. The affected packages are linux-nvidia, linux-nvidia-6.8 and linux-nvidia-lowlatency on Ubuntu 24.04 LTS and Ubuntu 22.04 LTS. Fixed builds are already in the archive at 6.8.0-1063.66 and 6.8.0-1063.66.1 for noble, and 6.8.0-1063.66~22.04.1 for jammy. For a reader who acted on the earlier notice, the change here is scope and naming, not a new class of problem.
The vendor has not published exploitation details for these issues, so there is no attack chain to describe and we will not invent one. What the notice does state is which subsystems were corrected: InfiniBand drivers, general network drivers, the TCM target subsystem, the B.A.T.M.A.N. meshing protocol, the HSR network protocol, IPv4 and IPv6 networking, Netfilter and the RDS protocol. That grouping is heavily weighted toward code that parses packets or handles kernel-level network state, which is the part of the kernel most often reachable from adjacent hosts or from local unprivileged processes holding network capabilities. Ubuntu describes the general outcome only as an attacker possibly being able to compromise the system. The update also carries an unavoidable ABI change, which means the kernel version number moves and third-party kernel modules built against the previous ABI will no longer match.
The practical exposure is concentrated in GPU compute estates: AI and machine-learning training nodes, rendering farms and NVIDIA-accelerated servers that run the specialised linux-nvidia kernel flavour rather than the generic one. These hosts tend to be long-lived, heavily scheduled and rebooted reluctantly, so kernel advisories on them routinely sit unapplied for weeks while a maintenance window is negotiated. Because the fix touches networking and storage-target subsystems, unpatched nodes in a shared cluster remain exposed to whatever traffic and tenants already reach them. On current exploitation status, FIRST EPSS places each of the scored CVEs between 0.5 and 0.8 percent probability of exploitation in the next thirty days, with CVE-2026-63994, CVE-2026-63912, CVE-2026-63888 and CVE-2026-63887 at the top of that band at 0.8 percent. None of these CVEs appear in any confirmed in-the-wild exploitation reporting available to us, and the low modelled probabilities are consistent with a routine coordinated fix rather than an active campaign. The ABI change is the operational sting: clusters that depend on out-of-tree drivers will have to rebuild them, and that dependency is the usual reason these patches slip.
Attack Surface
Server OS, Endpoint OS, Infrastructure
Tactics
Privilege Escalation, Impact, Lateral Movement
Techniques
- T1068 – Exploitation for Privilege Escalation
- T1210 – Exploitation of Remote Services
- T1499 – Endpoint Denial of Service
SuperPRO's Threat Countermeasures Procedures
- On Ubuntu 24.04 LTS (noble), upgrade to linux-image-6.8.0-1063-nvidia and linux-image-6.8.0-1063-nvidia-64k version 6.8.0-1063.66, and linux-image-6.8.0-1063-nvidia-lowlatency and its 64k variant to 6.8.0-1063.66.1, then reboot to load the fixed kernel.
- On Ubuntu 22.04 LTS (jammy), upgrade linux-image-6.8.0-1063-nvidia, linux-image-6.8.0-1063-nvidia-64k and the meta packages linux-image-nvidia-hwe-22.04 and linux-image-nvidia-64k-hwe-22.04 to 6.8.0-1063.66~22.04.1 and reboot.
- Because USN-8842-1 carries an ABI bump, rebuild and reinstall every third-party or out-of-tree kernel module on these hosts (including DKMS-built NVIDIA driver modules) after the upgrade; verify with 'uname -r' returning 6.8.0-1063-nvidia and 'dkms status' showing all modules installed against the new kernel.
- Inventory which hosts actually run the NVIDIA flavour rather than linux-generic by checking for the linux-nvidia, linux-nvidia-6.8 or linux-nvidia-lowlatency metapackages with 'dpkg -l | grep nvidia' — generic and virtual kernels are not addressed by this notice and need their own USN.
- Where reboot windows on GPU compute nodes cannot be met immediately, restrict reachability of the affected network paths: unload or blacklist unused modules such as batman-adv, hsr and rds via /etc/modprobe.d, and confirm iSCSI/TCM target ports (TCP/3260) are not exposed beyond the storage VLAN.
- Restrict CAP_NET_ADMIN and CAP_NET_RAW for containers and service accounts on unpatched nodes, and avoid running privileged containers on GPU hosts until the 6.8.0-1063 kernel is active, since several corrected subsystems are reachable from processes holding networking capabilities.
- Alert on kernel oops or panic entries in dmesg and journald referencing ib_core, target_core_mod, batman_adv, hsr, nf_tables or rds on these hosts, and on unexpected root shells spawned from low-privileged accounts on GPU compute nodes.