LSN-0122-1: live patch for dozens of use-after-free flaws in the Ubuntu kernel
Canonical releases live patch LSN-0122-1, fixing dozens of use-after-free and DoS bugs in the Linux kernel across all supported Ubuntu releases, with no reboot required.
UptimeMag editorial team · 7 October 2026 · 1 min read

On 7 October 2026, Canonical published advisory LSN-0122-1, a Kernel Live Patch Security Notice fixing dozens of vulnerabilities in the Ubuntu Linux kernel. For anyone running production servers, the headline news is this: the patches are applied via live patching, so there's no need for the reboot that would normally be required for a kernel update.
What the advisory covers
The list of affected packages is long and covers virtually every kernel used in hosting and cloud environments:
aws(>= 4.15.0-1159, >= 5.15.0-1000, >= 6.8.0-1008, >= 7.0.0-1000, >= 4.4.0-1159) andaws-6.8(>= 6.8.0-1000)azure(>= 5.15.0-1000, >= 6.8.0-1007, >= 7.0.0-1000, >= 4.15.0-1114)gcp(>= 5.15.0-1000, >= 6.8.0-1007, >= 7.0.0-1000, >= 4.15.0-1118) andgke(>= 5.15.0-1000, >= 6.8.0-1003)ibm(>= 5.15.0-1000, >= 6.8.0-1005)oracle(>= 4.15.0-1129, >= 6.8.0-1005)generic-4.15,generic-4.4,generic-5.4,lowlatencyand HWE variants
The Ubuntu releases affected are 26.04 LTS, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS and 16.04 LTS.
The flaws
The advisory text lists fix commits for use-after-free and type confusion bugs across several subsystems: filesystems (fs: dlm, ext4, jbd2), networking (net_sched hfsc/qfq/ets, netfilter nft_tunnel, vxlan vnifilter, geneve, page_pool, openvswitch), SMB (ksmbd, plus several distinct UAF bugs), RDMA (rxe, iwcm), crypto (algif_hash, padata), Wi-Fi drivers (brcmfmac, ath12k) and IPC (s390/pkey, ipc).
Among these, the bug in net_sched: hfsc: hfsc_dequeue is explicitly identified with CVE-2025-37823. For the others, the Ubuntu source text does not list a separate CVE identifier in the "Details" section of the advisory.
What to do
Anyone running Ubuntu Pro with kernel live patching enabled will receive the fix automatically, with no system reboot required. Anyone without live patching enabled needs to plan a conventional kernel upgrade, with a reboot, to the minimum versions listed above for their respective flavour.
The full text of the advisory, including the list of all upstream commits cited, is available on the official Ubuntu Security Notices site, on the LSN-0122-1 page.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.