StackPatch is liveSee product

Back to CVE digest
Ubuntu USN · USN-8547-2

Linux kernel (Azure FIPS) vulnerabilities

Published: Tue, 28 Jul 2026 06:37

CVE-2026-23190CVE-2026-43341CVE-2026-31669CVE-2025-71224CVE-2026-23256CVE-2026-23193CVE-2026-23450CVE-2026-43414CVE-2026-23428CVE-2026-23202CVE-2026-31478CVE-2026-31649CVE-2022-48816CVE-2026-23198CVE-2026-23206CVE-2026-23176CVE-2026-23216CVE-2026-31657CVE-2026-23180CVE-2026-46243CVE-2026-31682CVE-2026-46043CVE-2025-37822CVE-2023-53673CVE-2026-31607CVE-2026-43114CVE-2026-23258CVE-2025-71222CVE-2026-43493CVE-2026-45988CVE-2026-43383CVE-2025-37778CVE-2025-71220CVE-2026-23262CVE-2026-31418CVE-2026-31637CVE-2026-43071CVE-2026-43304CVE-2026-43117CVE-2026-43185CVE-2026-23455CVE-2026-31668CVE-2025-71089CVE-2026-31402CVE-2025-38201CVE-2026-43186CVE-2026-46119CVE-2026-46135CVE-2026-23182CVE-2026-43406CVE-2026-31685CVE-2025-68214CVE-2025-40082CVE-2026-43407CVE-2026-31659CVE-2026-43038CVE-2026-23278CVE-2026-43037CVE-2025-68263CVE-2026-43011CVE-2026-23272CVE-2026-43501CVE-2026-23257CVE-2026-46195CVE-2025-37924

Summary

Several security issues were fixed in the Linux kernel.

Details

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architecture; - Cryptographic API; - InfiniBand drivers; - IOMMU subsystem; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - x86 platform drivers; - SCSI subsystem; - SPI subsystem; - TCM subsystem; - USB over IP driver; - File systems infrastructure; - HFS+ file system; - Network file system (NFS) server daemon; - SMB network file system; - IPv6 networking; - Tracing infrastructure; - Timer subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Ethernet bridge; - Ceph Core library; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SMC sockets; - Sun RPC protocol; - X.25 network layer; - AMD SoC Alsa drivers; - KVM subsystem; (CVE-2022-48816, CVE-2023-53673, CVE-2025-37778, CVE-2025-37822, CVE-2025-37924, CVE-2025-38201, CVE-2025-40082, CVE-2025-68214, CVE-2025-68263, CVE-2025-71089, CVE-2025-71220, CVE-2025-71222, CVE-2025-71224, CVE-2026-23176, CVE-2026-23180, CVE-2026-23182, CVE-2026-23190, CVE-2026-23193, CVE-2026-23198, CVE-2026-23202, CVE-2026-23206, CVE-2026-23216, CVE-2026-23256, CVE-2026-23257, CVE-2026-23258, CVE-2026-23262, CVE-2026-23272, CVE-2026-23278, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455, CVE-2026-31402, CVE-2026-31418, CVE-2026-31478, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31669, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071, CVE-2026-43114, CVE-2026-43117, CVE-2026-43185, CVE-2026-43186, CVE-2026-43304, CVE-2026-43341, CVE-2026-43383, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43501, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46135, CVE-2026-46195, CVE-2026-46243)

Recommended actions per Ubuntu release

StackPatch playbook auto-generated per release codename and per affected package.

Ubuntu jammy

  • linux-azure-fips5.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-azure-fips5.15.0.1116.101apt_upgrade

    Standard apt upgrade. Install 5.15.0.1116.101 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-azure-fips-5.155.15.0.1116.101apt_upgrade

    Standard apt upgrade. Install 5.15.0.1116.101 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-azure-fips-5.15

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-azure-fips-cloud-tools-5.15.0-11165.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-azure-fips-cloud-tools-5.15.0-1116

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-azure-fips-headers-5.15.0-11165.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-azure-fips-headers-5.15.0-1116

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-azure-fips-tools-5.15.0-11165.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-azure-fips-tools-5.15.0-1116

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-buildinfo-5.15.0-1116-azure-fips5.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-buildinfo-5.15.0-1116-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-cloud-tools-5.15.0-1116-azure-fips5.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-cloud-tools-5.15.0-1116-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-cloud-tools-azure-fips5.15.0.1116.101apt_upgrade

    Standard apt upgrade. Install 5.15.0.1116.101 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-cloud-tools-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-cloud-tools-azure-fips-5.155.15.0.1116.101apt_upgrade

    Standard apt upgrade. Install 5.15.0.1116.101 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-cloud-tools-azure-fips-5.15

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-headers-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-headers-azure-fips5.15.0.1116.101kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-headers-azure-fips-5.155.15.0.1116.101kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-headers-azure-fips-5.15
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-azure-fips5.15.0.1116.101kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-azure-fips-5.155.15.0.1116.101kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-azure-fips-5.15
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-hmac-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-hmac-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-unsigned-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-unsigned-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-image-unsigned-hmac-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-image-unsigned-hmac-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-modules-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-modules-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-modules-extra-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-modules-extra-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-modules-extra-azure-fips5.15.0.1116.101kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-modules-extra-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-modules-extra-azure-fips-5.155.15.0.1116.101kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-modules-extra-azure-fips-5.15
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-modules-involflt-5.15.0-1116-azure-fips5.15.0-1116.125+fips1kernel_reboot

    Kernel package — apt-upgrade then REBOOT to load the patched kernel.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-modules-involflt-5.15.0-1116-azure-fips
    sudo reboot

    Reboot is required. ~30-60s downtime; containers self-restart.

  • linux-tools-5.15.0-1116-azure-fips5.15.0-1116.125+fips1apt_upgrade

    Standard apt upgrade. Install 5.15.0-1116.125+fips1 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-5.15.0-1116-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-tools-azure-fips5.15.0.1116.101apt_upgrade

    Standard apt upgrade. Install 5.15.0.1116.101 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-azure-fips

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • linux-tools-azure-fips-5.155.15.0.1116.101apt_upgrade

    Standard apt upgrade. Install 5.15.0.1116.101 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y linux-tools-azure-fips-5.15

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Are YOU affected by USN-8547-2?

5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8547-2 (and any other live CVE) applies. Anonymous, no signup.

curl https://mindsparkstack.com/scan.sh | bash
Want this automated for your servers?

StackPatch runs this match against YOUR installed packages every hour

Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.