LWN’s records date Ubuntu’s notices USN-8887-1 and USN-8889-1 to October 6, 2026. Debian’s earlier DSA-6528-1 specifies a different, release-specific fix: Linux package version 6.12.111-1 for stable Trixie. The details point to the same broad area—kernel security—but not to one package version that applies across distributions.
What the Ubuntu notices cover
LWN dates both Ubuntu notices to October 6. Its record for USN-8887-1 identifies CVE-2023-20585 and lists the linux, linux-aws, linux-gcp, linux-gke, linux-ibm, linux-oracle, and linux-realtime kernel flavors (USN-8887-1). A CVE is an identifier assigned to a security vulnerability.
For one specific case, the OSV record gives 7.0.0-1014.14 as a fixed-package example for linux-aws on Ubuntu 26.04 (USN-8887-1 package record). That example belongs to that Ubuntu release and kernel flavor.
The second notice has a different named scope: LWN identifies USN-8889-1 as concerning linux-oem-7.0 (USN-8889-1).
Debian’s fixed version applies to stable Trixie
Debian’s DSA-6528-1, dated September 29, 2026, says vulnerabilities in its linux package could lead to privilege escalation, denial of service, or information leaks. For stable Trixie, Debian identifies 6.12.111-1 as the fixed package version and recommends upgrading its Linux packages (DSA-6528-1).
The advisory also lists CVE-2026-80521 among its references, alongside other CVE identifiers. That means the Debian notice includes a vulnerability covered in earlier reporting on CVE-2026-80521, as well as additional entries.
Why an advisory can list many CVEs
Ton Does Linux offered context on the size of Debian’s list in an October 7 Linux news roundup. The presenter attributed it to two practices: the kernel project assigns CVE identifiers broadly to commits fixing potential security issues, and Debian stable groups fixes into periodic updates rather than shipping every upstream point release separately (Ton Does Linux’s roundup). That explanation is the presenter’s analysis, not a statement from Debian.