Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). ( CVE-2023-45896 ) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. ( CVE-2025-54505 ) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). ( CVE-2023-45896 )
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. ( CVE-2025-54505 )
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). ( CVE-2023-45896 ) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. ( CVE-2025-54505 ) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. ( CVE-2025-54518 ) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: ARM32 architecture; ARM64 architecture; MIPS architecture; PowerPC architecture; S390 architecture; x86 architecture; Block layer subsystem; Cryptographic API; ACPI drivers; ATM drivers; Drivers core; Power management core; DRBD Distributed Replicated Block Device drivers; RNBD block device driver; Bluetooth drivers; Bus devices; Character device driver; TPM device driver; Clocksource drivers; Data acquisition framework and drivers; CPU frequency scaling framework; CPU idle management framework; Hardware crypto device drivers; DMA engine subsystem; Arm Firmware Framework for ARMv8-A(FFA); EFI core; GPIO subsystem; GPU drivers; HID subsystem; Hardware monitoring drivers; I2C subsystem; IIO subsystem; IIO ADC drivers; InfiniBand drivers; Input Device (Miscellaneous) drivers; IOMMU subsystem; Mailbox framework; Multiple devices driver; Media drivers; MediaTek SMI driver; NVIDIA Tegra memory controller driver; Multifunction device drivers; IBM Advanced System Management driver; MMC subsystem; MTD block device drivers; Network drivers; Ethernet bonding driver; Mellanox network drivers; Microsoft Azure Network Adapter (MANA) driver; STMicroelectronics network drivers; MediaTek network drivers; Near Field Communication (NFC) drivers; NTB driver; NVDIMM (Non-Volatile Memory Device) drivers; NVME drivers; PCI subsystem; Pin controllers subsystem; x86 platform drivers; Broadcom BCM2835 power domain driver; Power supply drivers; RapidIO drivers; Remote Processor subsystem; RPMSG subsystem; SCSI subsystem; Freescale SoC drivers; Texas Instruments SoC drivers; SPI subsystem; Greybus lights staging drivers; Media staging drivers; Realtek RTL8723BS SDIO drivers; SM750 framebuffer staging driver; TCM subsystem; TTY drivers; UFS subsystem; Cadence USB3 driver; USB Device Class drivers; ULPI bus; USB core drivers; DesignWare USB2 driver; USB Gadget drivers; USB Host Controller drivers; Mustek MDC800 USB digital camera driver; USB YUREX driver; Renesas USBHS Controller drivers; Framebuffer layer; Xen hypervisor drivers; File systems infrastructure; BTRFS file system; Ceph distributed file system; EROFS file system; Ext4 file system; F2FS file system; FAT file system; FUSE (File system in Userspace); GFS2 file system; HFS+ file system; JFS file system; Network file system (NFS) server daemon; NILFS2 file system; File system notification infrastructure; NTFS3 file system; OCFS2 file system; Proc file system; Pstore file system; Diskquota system; SMB network file system; SquashFS file system; UDF file system; XFS file system; Audit subsystem; RAS (Reliability, Availability, Serviceability) subsystem; Memory Management; KVM subsystem; Memory management; PPP protocol drivers and compressors; Linux Security Modules (LSM) Framework; Network traffic control; Bluetooth subsystem; MAC80211 subsystem; Netfilter; IP tunnels definitions; Tracing infrastructure; User-space API (UAPI); io_uring subsystem; BPF subsystem; Control group (cgroup); Kernel fork() syscall; Kernel futex primitives; Kernel kexec() syscall; Kernel module support; Scheduler infrastructure; Cryptographic library; KASAN memory debugging framework; Asynchronous Transfer Mode (ATM) subsystem; B.A.T.M.A.N. meshing protocol; Ethernet bridge; CAIF protocol; CAN network layer; Ceph Core library; Networking core; Distributed Switch Architecture; IPv4 networking; IPv6 networking; XFRM subsystem; L2TP protocol; Management Component Transport Protocol (MCTP); Multipath TCP; NCSI (Network Controller Sideband Interface) driver; NFC subsystem; Open vSwitch; Phonet protocol; Qualcomm IPC Router (QRTR); RDS protocol; RF switch subsystem; Rose network layer; RxRPC session sockets; SCTP protocol; SMC sockets; Stream parser; Sun RPC protocol; TIPC protocol; TLS protocol; Unix domain sockets; VMware vSockets driver; Wireless networking; X.25 network layer; eXpress Data Path; AppArmor security module; Simplified Mandatory Access Control Kernel framework; ALSA framework; FireWire sound drivers; HD-audio driver; AudioScience HPI driver; Creative Sound Blaster X-Fi driver; AMD SoC Alsa drivers; SoC audio core drivers; STI ASoC drivers; USB sound devices
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). ( CVE-2023-45896 )
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. ( CVE-2025-54505 )
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. ( CVE-2025-54518 )
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
After a standard system update you need to reboot your computer to make all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.
The problem can be corrected by updating your system to the following package versions:
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
Have additional questions?
Talk to a member of the team ›
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
