USN-8851-3: linux-azure 5.4 kernel patch for Ubuntu 18.04 LTS, reboot required
Canonical fixes three CVEs in the linux-azure 5.4 kernel for Ubuntu 18.04 LTS: a reboot and rebuild of third-party modules are required.
UptimeMag editorial team · 5 October 2026 · 1 min read

Canonical published advisory USN-8851-3 on 5 October 2026, fixing three vulnerabilities in the Linux kernel for Microsoft Azure (linux-azure-5.4 package) on Ubuntu 18.04 LTS. This affects anyone still running Azure VMs on bionic with this kernel: without the update, the flaws remain exposed and, according to the official advisory, an attacker could exploit them to compromise the system.
What it fixes
The flaws affect three subsystems:
- the NFS (Network File System) server daemon;
- the IPv6 networking stack;
- Netfilter.
The CVEs cited in the advisory are CVE-2026-53221, CVE-2026-53131 and CVE-2025-38724.
Fixed versions
| Release | Package | Version |
|---|---|---|
| 18.04 LTS (bionic) | linux-image-5.4.0-1169-azure | 5.4.0-1169.175~18.04.1 |
| Ubuntu Pro | linux-image-azure | 5.4.0.1169.175~18.04.1 |
| Ubuntu Pro | linux-image-azure-5.4 | 5.4.0.1169.175~18.04.1 |
The two versions marked Ubuntu Pro are available only with an Ubuntu Pro subscription, as noted in the advisory.
Mandatory reboot and third-party modules
After the standard system update, the machine needs to be rebooted to apply the changes. The advisory also flags an unavoidable ABI change: the kernel has a new version number, so anyone who has installed third-party kernel modules must rebuild and reinstall them. Those who have not manually removed the standard metapackages (e.g. linux-generic, linux-virtual) will have this done automatically during the upgrade.
How to proceed
For anyone managing Azure VMs on Ubuntu 18.04 LTS:
sudo apt update && sudo apt upgrade
sudo reboot
After rebooting, check the running kernel version with uname -r and confirm it matches 5.4.0-1169-azure. Anyone using custom kernel modules (drivers, kernel-mode VPNs, additional filesystems) must rebuild them against the new ABI before relying on the system in production.
The full text of the advisory, along with the list of related notices, is available on the official Ubuntu Security Notices website (USN-8851-3).
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.