News

LSN-0122-1: live patch for dozens of use-after-free flaws in the Ubuntu kernel

Canonical releases live patch LSN-0122-1, fixing dozens of use-after-free and DoS bugs in the Linux kernel across all supported Ubuntu releases, with no reboot required.

UptimeMag editorial team · 7 October 2026 · 1 min read

LSN-0122-1: live patch per decine di falle use-after-free nel kernel Ubuntu

On 7 October 2026, Canonical published advisory LSN-0122-1, a Kernel Live Patch Security Notice fixing dozens of vulnerabilities in the Ubuntu Linux kernel. For anyone running production servers, the headline news is this: the patches are applied via live patching, so there's no need for the reboot that would normally be required for a kernel update.

What the advisory covers

The list of affected packages is long and covers virtually every kernel used in hosting and cloud environments:

  • aws (>= 4.15.0-1159, >= 5.15.0-1000, >= 6.8.0-1008, >= 7.0.0-1000, >= 4.4.0-1159) and aws-6.8 (>= 6.8.0-1000)
  • azure (>= 5.15.0-1000, >= 6.8.0-1007, >= 7.0.0-1000, >= 4.15.0-1114)
  • gcp (>= 5.15.0-1000, >= 6.8.0-1007, >= 7.0.0-1000, >= 4.15.0-1118) and gke (>= 5.15.0-1000, >= 6.8.0-1003)
  • ibm (>= 5.15.0-1000, >= 6.8.0-1005)
  • oracle (>= 4.15.0-1129, >= 6.8.0-1005)
  • generic-4.15, generic-4.4, generic-5.4, lowlatency and HWE variants

The Ubuntu releases affected are 26.04 LTS, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS and 16.04 LTS.

The flaws

The advisory text lists fix commits for use-after-free and type confusion bugs across several subsystems: filesystems (fs: dlm, ext4, jbd2), networking (net_sched hfsc/qfq/ets, netfilter nft_tunnel, vxlan vnifilter, geneve, page_pool, openvswitch), SMB (ksmbd, plus several distinct UAF bugs), RDMA (rxe, iwcm), crypto (algif_hash, padata), Wi-Fi drivers (brcmfmac, ath12k) and IPC (s390/pkey, ipc).

Among these, the bug in net_sched: hfsc: hfsc_dequeue is explicitly identified with CVE-2025-37823. For the others, the Ubuntu source text does not list a separate CVE identifier in the "Details" section of the advisory.

What to do

Anyone running Ubuntu Pro with kernel live patching enabled will receive the fix automatically, with no system reboot required. Anyone without live patching enabled needs to plan a conventional kernel upgrade, with a reboot, to the minimum versions listed above for their respective flavour.

The full text of the advisory, including the list of all upstream commits cited, is available on the official Ubuntu Security Notices site, on the LSN-0122-1 page.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.