Canonical published two Ubuntu 26.04 LTS kernel security notices on October 6, 2026, with fixed builds that vary by package flavor. USN-8887-1 covers seven kernel package families; USN-8889-1 covers the separate linux-oem-7.0 package. Canonical says to run a standard system update and then reboot for the changes to take effect (USN-8887-1; USN-8889-1).
Ubuntu 26.04 fixed builds by kernel flavor
Match the package flavor to its listed build: the versions in USN-8887-1 are not interchangeable across Ubuntu kernel families. USN-8889-1 lists the OEM build separately.
| Distribution and notice | Kernel package | Fixed package version |
| Ubuntu 26.04 LTS, USN-8887-1 | linux (generic) | 7.0.0-38.38 |
| Ubuntu 26.04 LTS, USN-8887-1 | linux-aws | 7.0.0-1014.14 |
| Ubuntu 26.04 LTS, USN-8887-1 | linux-gcp | 7.0.0-1014.14 |
| Ubuntu 26.04 LTS, USN-8887-1 | linux-gke | 7.0.0-1008.9 |
| Ubuntu 26.04 LTS, USN-8887-1 | linux-ibm | 7.0.0-1015.15 |
| Ubuntu 26.04 LTS, USN-8887-1 | linux-oracle | 7.0.0-1013.13 |
| Ubuntu 26.04 LTS, USN-8887-1 | linux-realtime | 7.0.0-38.38.1 |
| Ubuntu 26.04 LTS, USN-8889-1 | linux-oem-7.0 | 7.0.0-1015.15 |
Canonical’s tables also list package variants such as signed images, 64K builds and metapackages. The versions above identify the named kernel families; administrators should match the package family in their system to the corresponding notice entry.
CVE-2023-20585 and its stated prerequisites
Both Ubuntu notices describe CVE-2023-20585, an issue involving Reverse Map Table (RMP) checks on some AMD processors when the IOMMU accesses certain host buffers. Canonical says exploitation requires a local attacker who already has hypervisor access; the possible impact is compromised memory integrity for SEV-SNP guests (USN-8887-1; USN-8889-1).
Update, reboot and third-party modules
Canonical’s instructions are to apply a standard system update and reboot. The notices also warn that an ABI change may require third-party kernel modules to be recompiled and reinstalled. A standard upgrade handles that work when the relevant standard kernel metapackages have not been manually removed (USN-8887-1; USN-8889-1).
Debian Trixie has a separate fixed version
Debian’s DSA-6528-1, published September 29, 2026, lists 6.12.111-1 as the fixed version for the linux package in stable Debian 13 “Trixie” and recommends upgrading the package. Debian says the vulnerabilities addressed by the advisory could allow privilege escalation, denial of service or information disclosure (DSA-6528-1).