StackPatch is liveSee product

Back to CVE digest
Ubuntu USN · USN-8499-1

Linux kernel (Xilinx) vulnerabilities

Published: Thu, 02 Jul 2026 15:56

CVE-2026-43314CVE-2026-45974CVE-2025-71291CVE-2026-45870CVE-2026-43341CVE-2026-47332CVE-2026-23229CVE-2026-47326CVE-2026-23176CVE-2026-23099CVE-2026-45861CVE-2026-43199CVE-2026-45869CVE-2026-43077CVE-2026-43173CVE-2026-23142CVE-2025-71295CVE-2026-23030CVE-2026-23222CVE-2025-71222CVE-2026-43133CVE-2026-45978CVE-2026-23097CVE-2024-58097CVE-2026-23150CVE-2026-46289CVE-2025-71185CVE-2026-23262CVE-2026-46115CVE-2026-46266CVE-2026-23179CVE-2025-71297CVE-2025-68803CVE-2026-23234CVE-2026-45916CVE-2026-43157CVE-2026-31668CVE-2026-23241CVE-2026-23091CVE-2026-23010CVE-2026-43302CVE-2026-31504CVE-2026-43221CVE-2025-71292CVE-2026-23084CVE-2026-23021CVE-2026-23095CVE-2026-43238CVE-2026-45851CVE-2026-43225CVE-2026-45895CVE-2026-45948CVE-2026-45973CVE-2026-43123CVE-2026-43148CVE-2026-23005CVE-2026-43406CVE-2025-71294CVE-2026-23075CVE-2026-43256CVE-2026-43150CVE-2026-43205CVE-2026-23058CVE-2026-23178CVE-2026-31436CVE-2026-43279CVE-2026-23206CVE-2025-71186CVE-2026-23110CVE-2025-71162CVE-2026-45981CVE-2026-23061CVE-2026-23139CVE-2026-45882CVE-2026-23088CVE-2026-31533CVE-2026-45880CVE-2026-43184CVE-2026-22999CVE-2026-31693CVE-2026-47328CVE-2026-47329CVE-2026-23003CVE-2026-23069CVE-2025-71235CVE-2026-43159CVE-2026-43231CVE-2026-43212CVE-2026-45919CVE-2026-43158CVE-2025-40082CVE-2026-23101CVE-2026-43145CVE-2026-23113CVE-2026-23236CVE-2026-46328CVE-2026-23136CVE-2026-45910CVE-2026-23100CVE-2026-45954CVE-2025-71163CVE-2026-23120CVE-2026-46246CVE-2026-23257CVE-2025-68749CVE-2026-23392CVE-2026-31657CVE-2026-45852CVE-2026-23191CVE-2026-22976CVE-2025-71199CVE-2026-23090CVE-2026-46265CVE-2026-23064CVE-2025-37926CVE-2026-23032CVE-2026-23019CVE-2026-43257CVE-2026-23049CVE-2026-23056CVE-2026-23116CVE-2026-22991CVE-2025-71195CVE-2026-43128CVE-2026-23266CVE-2026-23038CVE-2026-43233CVE-2026-43011CVE-2025-71273CVE-2026-23141CVE-2026-43169CVE-2025-71232CVE-2025-71182CVE-2026-23167CVE-2026-23351CVE-2024-50004CVE-2026-45935CVE-2026-43139CVE-2026-45912CVE-2026-45857CVE-2026-45902CVE-2026-43033CVE-2026-23220CVE-2026-43156CVE-2026-43317CVE-2026-43258CVE-2026-23214CVE-2026-23151CVE-2026-23071CVE-2026-22982CVE-2026-23068CVE-2026-46270CVE-2025-71194CVE-2026-23059CVE-2026-23031CVE-2026-43182CVE-2026-43304CVE-2026-22980CVE-2025-71265CVE-2026-23107CVE-2026-46300CVE-2025-71305CVE-2026-23172CVE-2026-22998CVE-2026-43186CVE-2026-43283CVE-2026-22984CVE-2026-43414CVE-2026-23170CVE-2026-23037CVE-2026-23087CVE-2026-43494CVE-2026-45860CVE-2026-45998CVE-2025-38591CVE-2026-23180CVE-2026-43262CVE-2026-47330CVE-2026-43268CVE-2026-43170CVE-2025-71267CVE-2026-45893CVE-2026-31431CVE-2026-23233CVE-2026-23103CVE-2026-45914CVE-2026-23238CVE-2026-43189CVE-2026-23140CVE-2026-23230CVE-2025-71272CVE-2026-43255CVE-2026-43289CVE-2026-23450CVE-2025-68823CVE-2026-43167CVE-2026-23078CVE-2026-31402CVE-2026-43130CVE-2026-31687CVE-2026-43249CVE-2026-23054CVE-2026-23145CVE-2026-43211CVE-2026-43168CVE-2026-22990CVE-2026-45884CVE-2026-43271CVE-2026-23146CVE-2026-23020CVE-2026-45983CVE-2026-46195CVE-2026-23119CVE-2025-71184CVE-2026-45936CVE-2026-31682CVE-2026-31649CVE-2026-43132CVE-2026-23050CVE-2026-23237CVE-2025-71304CVE-2026-45891CVE-2026-43147CVE-2025-68365CVE-2026-45947CVE-2026-43226CVE-2026-43383CVE-2026-31607CVE-2026-43384CVE-2025-38201CVE-2026-45988CVE-2026-23394CVE-2026-23126CVE-2026-23135CVE-2026-31669CVE-2026-43209CVE-2026-23215CVE-2026-23264CVE-2025-40039CVE-2026-45862CVE-2026-43180CVE-2026-23065CVE-2025-71233CVE-2026-46261CVE-2025-71268CVE-2026-23190CVE-2026-43284CVE-2026-46251CVE-2025-71183CVE-2025-71192CVE-2026-23164CVE-2026-23166CVE-2026-23053CVE-2026-45921CVE-2026-43187CVE-2026-23156CVE-2026-23159CVE-2026-43038CVE-2026-23131CVE-2026-43200CVE-2026-23133CVE-2026-43078CVE-2026-45969CVE-2026-23173CVE-2026-43218CVE-2026-23033CVE-2026-47331CVE-2026-43222CVE-2026-43114CVE-2026-23073CVE-2025-71188CVE-2026-45877CVE-2026-23228CVE-2025-71238CVE-2026-45960CVE-2026-43241CVE-2026-23193CVE-2026-45849CVE-2026-31448CVE-2026-23254CVE-2026-45962CVE-2026-46135CVE-2026-45872CVE-2026-46119CVE-2026-23098CVE-2026-43300CVE-2026-43124CVE-2026-43287CVE-2026-23216CVE-2026-43275CVE-2026-23256CVE-2026-47333CVE-2026-22992CVE-2026-23274CVE-2026-43152CVE-2026-43037CVE-2025-71231CVE-2026-23258CVE-2026-22978CVE-2026-46249CVE-2026-23025CVE-2026-23260CVE-2026-23204CVE-2026-23278CVE-2025-71239CVE-2026-47337CVE-2025-71196CVE-2026-23105CVE-2026-43183CVE-2026-31637CVE-2026-43296CVE-2025-40149CVE-2026-23085CVE-2026-46185CVE-2026-43215CVE-2026-45847CVE-2026-23243CVE-2026-31659CVE-2026-45883CVE-2026-23235CVE-2026-46253CVE-2026-31411CVE-2026-22994CVE-2026-43190CVE-2026-45928CVE-2025-68725CVE-2025-68358CVE-2026-45856CVE-2025-71236CVE-2026-43140CVE-2026-43143CVE-2026-43501CVE-2026-45941CVE-2026-45886CVE-2026-43503CVE-2026-43227CVE-2026-23160CVE-2026-43318CVE-2026-43196CVE-2026-43171CVE-2025-71189CVE-2026-23242CVE-2026-43288CVE-2026-43236CVE-2026-43246CVE-2026-23096CVE-2025-71229CVE-2026-43202CVE-2026-43136CVE-2026-43135CVE-2026-23125CVE-2026-45868CVE-2026-45904CVE-2026-23128CVE-2026-23144CVE-2025-71191CVE-2026-45915CVE-2026-46247CVE-2026-45871CVE-2026-45946CVE-2026-23169CVE-2026-43270CVE-2026-43500CVE-2026-43316CVE-2026-23261CVE-2026-43244CVE-2026-43278CVE-2025-71286CVE-2026-46259CVE-2026-22977CVE-2026-43071CVE-2026-23089CVE-2025-71160CVE-2026-46043CVE-2026-23062CVE-2026-23221CVE-2025-71220CVE-2026-23026CVE-2026-43137CVE-2026-45970CVE-2026-23123CVE-2025-71193CVE-2025-68351CVE-2026-23124CVE-2026-43248CVE-2026-46250CVE-2026-31419CVE-2026-43291CVE-2026-23200CVE-2026-23249CVE-2026-43313CVE-2026-43206CVE-2026-43320CVE-2026-23001CVE-2026-23168CVE-2026-45965CVE-2025-71225CVE-2026-45982CVE-2026-43378CVE-2026-43319CVE-2026-23086CVE-2026-23148CVE-2026-46000CVE-2026-23129CVE-2026-23428CVE-2026-45865CVE-2026-43134CVE-2026-43175CVE-2026-23083CVE-2026-43312CVE-2026-23267CVE-2026-47335CVE-2025-40005CVE-2026-45867CVE-2026-43194CVE-2026-46244CVE-2026-45964CVE-2026-43223CVE-2025-71266CVE-2026-43117CVE-2026-46323CVE-2026-43251CVE-2026-43277CVE-2026-23047CVE-2026-23212CVE-2026-45923CVE-2026-43269CVE-2026-23011CVE-2026-45864CVE-2026-23063CVE-2026-45881CVE-2026-22996CVE-2026-43163CVE-2026-23080CVE-2026-31685CVE-2026-45873CVE-2025-71224CVE-2026-23102CVE-2026-45890CVE-2026-45875CVE-2026-43407CVE-2026-23202CVE-2025-71200CVE-2025-71180CVE-2026-46267CVE-2026-43153CVE-2026-45968CVE-2026-46255CVE-2025-71274CVE-2026-45913CVE-2026-43266CVE-2026-46254CVE-2026-23000CVE-2026-43239CVE-2026-23121CVE-2026-43207CVE-2026-43261CVE-2026-23076CVE-2026-43149CVE-2026-43250CVE-2026-45878CVE-2026-46028CVE-2026-22997CVE-2026-43214CVE-2026-45984CVE-2026-43297CVE-2026-23187CVE-2026-45905CVE-2026-45938CVE-2025-71237CVE-2026-43141CVE-2026-23108CVE-2026-31418CVE-2026-45976CVE-2026-43232CVE-2026-31478CVE-2026-23006CVE-2026-23093CVE-2024-58096CVE-2025-71198CVE-2026-23455CVE-2026-43273CVE-2026-23272CVE-2025-71197CVE-2026-22979CVE-2026-43203CVE-2026-43295CVE-2026-45859CVE-2026-45957CVE-2026-45885CVE-2026-43230CVE-2026-46243CVE-2026-23057CVE-2026-43493CVE-2026-23213CVE-2026-23205CVE-2026-47327CVE-2026-47334CVE-2026-45879CVE-2026-45848CVE-2026-31676CVE-2026-23182CVE-2026-43242CVE-2026-23163CVE-2026-43315CVE-2025-71190CVE-2026-23094CVE-2026-43201CVE-2026-43264CVE-2026-46333CVE-2026-45866CVE-2026-23198CVE-2026-23035CVE-2026-47336CVE-2026-45917CVE-2026-43253

Summary

Several security issues were fixed in the Linux kernel.

Details

It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500, CVE-2026-45998, CVE-2026-46000) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503, CVE-2026-46300) Qualys discovered that a race condition existed in the ptrace subsystem of the Linux kernel when privileged processes are exiting. An unprivileged local attacker could use this issue to expose sensitive information. (CVE-2026-46333) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contain a memory leak when handling AppArmor notifications. A local attacker could use this to cause resource exhaustion. (CVE-2026-47326) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contain a NULL pointer dereference when handling AppArmor notifications. A local attacker could use this to cause a kernel oops. (CVE-2026-47327) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained an invalid free when handling AppArmor notifications. A local attacker could use this to corrupt kernel memory. (CVE-2026-47328) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained insufficient validation of AppArmor notification responses. A local attacker could use this to allow crafted responses to be processed. (CVE-2026-47329) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 used an uninitialized variable when handling AppArmor notifications. A local attacker could use this to cause incorrect caching of data. (CVE-2026-47330) Tristan Madani discovered that Ubuntu Linux kernel 6.8 contained a use- after-free (UAF) bug. A local attacker could use this to cause memory corruption and, theoretically, arbitrary code execution. (CVE-2026-47331) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained an out-of-bounds (OOB) read when handling AppArmor notifications. A local attacker could use this to cause information disclosure of kernel memory. (CVE-2026-47332) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a out-of-bounds (OOB) read when handling AppArmor notifications. A local attacker could use this to cause kernel memory corruption and, theoretically, influence processing of AppArmor policies. (CVE-2026-47333) Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained incorrect holding of locks when handling AppArmor notifications. A local attacker could use this to cause a kernel panic or deadlock. (CVE-2026-47334) Tristan Madani discovered that Ubuntu Linux kernel 6.8 contained a NULL pointer dereference when handling AppArmor notifications. A local attacker could use this to cause a kernel panic. (CVE-2026-47335) Tristan Madani discovered that Ubuntu Linux kernel 6.8 used an uninitialized variable when handling AppArmor AF_INET/AF_INET6 socket mediation. A local attacker could use this to influence processing of fine- grained network socket mediation. (CVE-2026-47336) Tristan Madani and Trevor Lawrence have each independently discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a NULL pointer dereference when handling AppArmor network socket mediation. A local attacker could use this to cause a kernel oops. (CVE-2026-47337) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Intel NPU Driver; - ACPI drivers; - ATM drivers; - Drivers core; - Null block device driver; - RNBD block device driver; - Ublk userspace block driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clock framework and drivers; - Clocksource drivers; - Counter interface drivers; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - DPLL subsystem; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - Intel Trace Hub HW tracing drivers; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - On-Chip Interconnect management framework; - IOMMU subsystem; - IRQ chip drivers; - Modular ISDN driver; - LED subsystem; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - Broadcom VK accelerator driver; - UACCE accelerator framework; - MMC subsystem; - MOST (Media Oriented Systems Transport) drivers; - MTD block device drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NTB driver; - NVME drivers; - PCI subsystem; - Performance monitor drivers; - PHY drivers; - Pin controllers subsystem; - x86 platform drivers; - i.MX PM domains; - Power supply drivers; - RapidIO drivers; - RAS (Reliability, Availability, Serviceability) subsystem; - Remote Processor subsystem; - RPMSG subsystem; - S/390 drivers; - SCSI subsystem; - SLIMbus drivers; - MediaTek SoC drivers; - Texas Instruments SoC drivers; - SPI subsystem; - Greybus lights staging drivers; - Realtek RTL8723BS SDIO drivers; - TCM subsystem; - UFS subsystem; - ChipIdea USB driver; - DesignWare USB3 driver; - USB over IP driver; - vDPA drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - W1 Dallas's 1-wire bus driver; - Xen hypervisor drivers; - BTRFS file system; - File systems infrastructure; - Ceph distributed file system; - EFI Variable file system; - exFAT file system; - Ext4 file system; - F2FS file system; - FAT file system; - GFS2 file system; - HFS+ file system; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - OCFS2 file system; - Proc file system; - Pstore file system; - Diskquota system; - SMB network file system; - XFS file system; - Audit subsystem; - Memory Management; - Scheduler infrastructure; - IPv6 networking; - Netfilter; - NFC subsystem; - Tracing infrastructure; - io_uring subsystem; - BPF subsystem; - Perf events; - Kernel kexec() syscall; - RCU subsystem; - Floating proportions library; - Scatterlist API; - Memory management; - 9P file system network protocol; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Ethernet bridge; - CAN network layer; - Ceph Core library; - Networking core; - IPv4 networking; - KCM (Kernel Connection Multiplexor) sockets driver; - L2TP protocol; - MAC80211 subsystem; - Multipath TCP; - NET/ROM layer; - Packet sockets; - RDS protocol; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - Sun RPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - X.25 network layer; - XFRM subsystem; - AppArmor security module; - Simplified Mandatory Access Control Kernel framework; - ALSA AC97 driver; - Generic PCM loopback sound driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - Texas InstrumentS Audio (ASoC/HDA) drivers; - SOF drivers; - USB sound devices; - KVM subsystem; (CVE-2024-50004, CVE-2024-58096, CVE-2024-58097, CVE-2025-37926, CVE-2025-38201, CVE-2025-38591, CVE-2025-40005, CVE-2025-40039, CVE-2025-40082, CVE-2025-40149, CVE-2025-68351, CVE-2025-68358, CVE-2025-68365, CVE-2025-68725, CVE-2025-68749, CVE-2025-68803, CVE-2025-68823, CVE-2025-71160, CVE-2025-71162, CVE-2025-71163, CVE-2025-71180, CVE-2025-71182, CVE-2025-71183, CVE-2025-71184, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71192, CVE-2025-71193, CVE-2025-71194, CVE-2025-71195, CVE-2025-71196, CVE-2025-71197, CVE-2025-71198, CVE-2025-71199, CVE-2025-71200, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2025-71225, CVE-2025-71229, CVE-2025-71231, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235, CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71268, CVE-2025-71272, CVE-2025-71273, CVE-2025-71274, CVE-2025-71286, CVE-2025-71291, CVE-2025-71292, CVE-2025-71294, CVE-2025-71295, CVE-2025-71297, CVE-2025-71304, CVE-2025-71305, CVE-2026-22976, CVE-2026-22977, CVE-2026-22978, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22984, CVE-2026-22990, CVE-2026-22991, CVE-2026-22992, CVE-2026-22994, CVE-2026-22996, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23000, CVE-2026-23001, CVE-2026-23003, CVE-2026-23005, CVE-2026-23006, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23020, CVE-2026-23021, CVE-2026-23025, CVE-2026-23026, CVE-2026-23030, CVE-2026-23031, CVE-2026-23032, CVE-2026-23033, CVE-2026-23035, CVE-2026-23037, CVE-2026-23038, CVE-2026-23047, CVE-2026-23049, CVE-2026-23050, CVE-2026-23053, CVE-2026-23054, CVE-2026-23056, CVE-2026-23057, CVE-2026-23058, CVE-2026-23059, CVE-2026-23061, CVE-2026-23062, CVE-2026-23063, CVE-2026-23064, CVE-2026-23065, CVE-2026-23068, CVE-2026-23069, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23086, CVE-2026-23087, CVE-2026-23088, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23094, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23100, CVE-2026-23101, CVE-2026-23102, CVE-2026-23103, CVE-2026-23105, CVE-2026-23107, CVE-2026-23108, CVE-2026-23110, CVE-2026-23113, CVE-2026-23116, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23123, CVE-2026-23124, CVE-2026-23125, CVE-2026-23126, CVE-2026-23128, CVE-2026-23129, CVE-2026-23131, CVE-2026-23133, CVE-2026-23135, CVE-2026-23136, CVE-2026-23139, CVE-2026-23140, CVE-2026-23141, CVE-2026-23142, CVE-2026-23144, CVE-2026-23145, CVE-2026-23146, CVE-2026-23148, CVE-2026-23150, CVE-2026-23151, CVE-2026-23156, CVE-2026-23159, CVE-2026-23160, CVE-2026-23163, CVE-2026-23164, CVE-2026-23166, CVE-2026-23167, CVE-2026-23168, CVE-2026-23169, CVE-2026-23170, CVE-2026-23172, CVE-2026-23173, CVE-2026-23176, CVE-2026-23178, CVE-2026-23179, CVE-2026-23180, CVE-2026-23182, CVE-2026-23187, CVE-2026-23190, CVE-2026-23191, CVE-2026-23193, CVE-2026-23198, CVE-2026-23200, CVE-2026-23202, CVE-2026-23204, CVE-2026-23205, CVE-2026-23206, CVE-2026-23212, CVE-2026-23213, CVE-2026-23214, CVE-2026-23215, CVE-2026-23216, CVE-2026-23220, CVE-2026-23221, CVE-2026-23222, CVE-2026-23228, CVE-2026-23229, CVE-2026-23230, CVE-2026-23233, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23249, CVE-2026-23254, CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23260, CVE-2026-23261, CVE-2026-23262, CVE-2026-23264, CVE-2026-23266, CVE-2026-23267, CVE-2026-23272, CVE-2026-23274, CVE-2026-23278, CVE-2026-23351, CVE-2026-23392, CVE-2026-23394, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455, CVE-2026-31402, CVE-2026-31411, CVE-2026-31418, CVE-2026-31419, CVE-2026-31436, CVE-2026-31448, CVE-2026-31478, CVE-2026-31504, CVE-2026-31533, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31669, CVE-2026-31676, CVE-2026-31682, CVE-2026-31685, CVE-2026-31687, CVE-2026-31693, CVE-2026-43011, CVE-2026-43033, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071, CVE-2026-43077, CVE-2026-43078, CVE-2026-43114, CVE-2026-43117, CVE-2026-43123, CVE-2026-43124, CVE-2026-43128, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43137, CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43143, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43150, CVE-2026-43152, CVE-2026-43153, CVE-2026-43156, CVE-2026-43157, CVE-2026-43158, CVE-2026-43159, CVE-2026-43163, CVE-2026-43167, CVE-2026-43168, CVE-2026-43169, CVE-2026-43170, CVE-2026-43171, CVE-2026-43173, CVE-2026-43175, CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43186, CVE-2026-43187, CVE-2026-43189, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43199, CVE-2026-43200, CVE-2026-43201, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211, CVE-2026-43212, CVE-2026-43214, CVE-2026-43215, CVE-2026-43218, CVE-2026-43221, CVE-2026-43222, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43238, CVE-2026-43239, CVE-2026-43241, CVE-2026-43242, CVE-2026-43244, CVE-2026-43246, CVE-2026-43248, CVE-2026-43249, CVE-2026-43250, CVE-2026-43251, CVE-2026-43253, CVE-2026-43255, CVE-2026-43256, CVE-2026-43257, CVE-2026-43258, CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43271, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43278, CVE-2026-43279, CVE-2026-43283, CVE-2026-43287, CVE-2026-43288, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295, CVE-2026-43296, CVE-2026-43297, CVE-2026-43300, CVE-2026-43302, CVE-2026-43304, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43317, CVE-2026-43318, CVE-2026-43319, CVE-2026-43320, CVE-2026-43341, CVE-2026-43378, CVE-2026-43383, CVE-2026-43384, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43494, CVE-2026-43501, CVE-2026-45847, CVE-2026-45848, CVE-2026-45849, CVE-2026-45851, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45859, CVE-2026-45860, CVE-2026-45861, CVE-2026-45862, CVE-2026-45864, CVE-2026-45865, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45872, CVE-2026-45873, CVE-2026-45875, CVE-2026-45877, CVE-2026-45878, CVE-2026-45879, CVE-2026-45880, CVE-2026-45881, CVE-2026-45882, CVE-2026-45883, CVE-2026-45884, CVE-2026-45885, CVE-2026-45886, CVE-2026-45890, CVE-2026-45891, CVE-2026-45893, CVE-2026-45895, CVE-2026-45902, CVE-2026-45904, CVE-2026-45905, CVE-2026-45910, CVE-2026-45912, CVE-2026-45913, CVE-2026-45914, CVE-2026-45915, CVE-2026-45916, CVE-2026-45917, CVE-2026-45919, CVE-2026-45921, CVE-2026-45923, CVE-2026-45928, CVE-2026-45935, CVE-2026-45936, CVE-2026-45938, CVE-2026-45941, CVE-2026-45946, CVE-2026-45947, CVE-2026-45948, CVE-2026-45954, CVE-2026-45957, CVE-2026-45960, CVE-2026-45962, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45973, CVE-2026-45974, CVE-2026-45976, CVE-2026-45978, CVE-2026-45981, CVE-2026-45982, CVE-2026-45983, CVE-2026-45984, CVE-2026-45988, CVE-2026-46028, CVE-2026-46043, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243, CVE-2026-46244, CVE-2026-46246, CVE-2026-46247, CVE-2026-46249, CVE-2026-46250, CVE-2026-46251, CVE-2026-46253, CVE-2026-46254, CVE-2026-46255, CVE-2026-46259, CVE-2026-46261, CVE-2026-46265, CVE-2026-46266, CVE-2026-46267, CVE-2026-46270, CVE-2026-46289, CVE-2026-46323, CVE-2026-46328)

Recommended actions per Ubuntu release

StackPatch playbook auto-generated per release codename and per affected package.

Ubuntu noble

  • linux-xilinx6.8.0-1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0-1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-xilinx

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-buildinfo-6.8.0-1032-xilinx6.8.0-1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0-1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-buildinfo-6.8.0-1032-xilinx

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-headers-6.8.0-1032-xilinx6.8.0-1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-6.8.0-1032-xilinx
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-headers-xilinx6.8.0.1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-xilinx
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-headers-xilinx-6.86.8.0.1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-xilinx-6.8
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-headers-xilinx-zynqmp6.8.0.1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-xilinx-zynqmp
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-6.8.0-1032-xilinx6.8.0-1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-6.8.0-1032-xilinx
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-xilinx6.8.0.1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-xilinx
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-xilinx-6.86.8.0.1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-xilinx-6.8
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-xilinx-zynqmp6.8.0.1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-xilinx-zynqmp
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-modules-6.8.0-1032-xilinx6.8.0-1032.33kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-modules-6.8.0-1032-xilinx
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-tools-6.8.0-1032-xilinx6.8.0-1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0-1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-6.8.0-1032-xilinx

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-tools-xilinx6.8.0.1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0.1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-xilinx

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-tools-xilinx-6.86.8.0.1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0.1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-xilinx-6.8

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-tools-xilinx-zynqmp6.8.0.1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0.1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-xilinx-zynqmp

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-xilinx6.8.0.1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0.1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-xilinx

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-xilinx-6.86.8.0.1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0.1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-xilinx-6.8

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-xilinx-headers-6.8.0-10326.8.0-1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0-1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-xilinx-headers-6.8.0-1032

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-xilinx-tools-6.8.0-10326.8.0-1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0-1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-xilinx-tools-6.8.0-1032

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-xilinx-zynqmp6.8.0.1032.33apt_upgrade

    Standard apt upgrade. Install 6.8.0.1032.33 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-xilinx-zynqmp

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Are YOU affected by USN-8499-1?

5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8499-1 (and any other live CVE) applies. Anonymous, no signup.

curl https://mindsparkstack.com/scan.sh | bash
Want this automated for your servers?

StackPatch runs this match against YOUR installed packages every hour

Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.