USN-8889-1: Linux kernel (OEM) vulnerabilities
Checked 7 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · USN-8889-1
USN-8889-1: Linux kernel (OEM) vulnerabilities
Scope: Ubuntu. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - NVDIMM (Non-Volatile Memory Device) drivers; - Handshake API; - ARM32 architecture; - MIPS architecture; - OpenRISC architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Cryptographic API; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Serial ATA and Parallel ATA drivers; - Drivers core; - Rados block device (RBD) driver; - Ublk userspace block driver; - Bluetooth drivers; - Cdrom driver; - Character device driver; - TPM device driver; - Data acquisition framework and drivers; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - DAX dirext access to differentiated memory framework; - DIBS (Direct Internal Buffer Sharing) drivers; - Buffer Sharing and Synchronization framework; - DMA engine subsystem; - DPLL subsystem; - EDAC drivers; - FireWire subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - ARM SCMI message protocol; - Intel Stratix 10 firmware drivers; - FPGA Framework; - GPIB drivers; - GPIO subsystem; - GPU drivers; - HID subsystem; - Microsoft Hyper-V drivers; - Hardware monitoring drivers; - CoreSight HW tracing drivers; - Intel Trace Hub HW tracing drivers; - I2C subsystem; - I3C subsystem; - IIO subsystem; - IIO ADC drivers; - IIO Magnetometer sensors drivers; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - IRQ chip drivers; - LED subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MemoryStick subsystem; - Multifunction device drivers; - Intel Management Engine Interface driver; - Amazon Nitro Secure Module driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - Ethernet bonding driver; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - Texas Instruments network drivers; - MediaTek network drivers; - NTB driver; - NVME drivers; - Device tree and open firmware driver; - Operating Performance Points (OPP) driver; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - i.MX PM domains; - MediaTek PM domains; - Power supply drivers; - PTP clock framework; - RapidIO drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - MPAM driver; - Reset controller framework; - Real Time Clock drivers; - S/390 drivers; - SCSI subsystem; - Xilinx SoC drivers; - SoundWire subsystem; - SPI subsystem; - Media staging drivers; - Media Oriented Systems Transport (MOST) driver; - NVIDIA Tegra embedded controller (NVEC) staging driver; - Realtek RTL8723BS SDIO drivers; - TTY drivers; - UFS subsystem; - USB DSL drivers; - USB core drivers; - DesignWare USB3 driver; - USB Gadget drivers; - USB Host Controller drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - vDPA drivers; - VFIO drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - Virtio drivers; - Watchdog drivers; - Xen hypervisor drivers; - 9P distributed file system; - AFS file system; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - FUSE (File system in Userspace); - Journaling layer for block devices (JBD2); - Network file systems library; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - OCFS2 file system; - Overlay file system; - Proc file system; - SMB network file system; - BPF subsystem; - File system encryption (fscrypt); - MAC80211 subs
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.
Checked 7 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source