Back Linuxsecurity Ubuntu 14.04 LTS Important Network Privilege Escalation - USN-8635
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - GPU drivers; - InfiniBand dri... Read the Full Advisory
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS linux-image-4.15.0-1205-azure 4.15.0-1205.220~14.04.1 Available with Ubuntu Pro linux-image-azure 4.15.0.1205.220~14.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.
CVE-2021-47202, CVE-2021-47354, CVE-2021-47378, CVE-2024-38612,
CVE-2024-56643, CVE-2025-27558, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448,
CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657,
CVE-2026-31659, CVE-2026-31668, CVE-2026-31682, CVE-2026-31685,
CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43198,
CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493,
CVE-2026-43499, CVE-2026-43503, CVE-2026-45988, CVE-2026-46043,
CVE-2026-46119, CVE-2026-46243, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982,
CVE-2026-52986, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045,
CVE-2026-53088, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228,
Ubuntu Security Notice USN-8635-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
