USN-8864-1: Linux kernel flaws, patch for Ubuntu 16.04 and 14.04 LTS
Ubuntu fixes three CVEs in the Linux kernel for the 16.04 and 14.04 LTS releases. A reboot and recompilation of third-party modules are required.
UptimeMag editorial team · 2 October 2026 · 1 min read

Ubuntu published security notice USN-8864-1 on 2 October 2026, fixing three vulnerabilities in the Linux kernel for the 16.04 LTS (Xenial) and 14.04 LTS (Trusty) releases, according to the official advisory. Anyone still running servers on these versions, typically legacy machines kept alive with Ubuntu Pro, needs to plan for the update and reboot.
What it fixes
The advisory flags three CVEs: CVE-2026-53221, CVE-2026-53131 and CVE-2025-38724. The issues concern the NFS (Network File System) server daemon, IPv6 network handling and the Netfilter framework. According to the text of the advisory, an attacker could exploit these flaws to compromise the system.
Affected packages
The update touches the linux, linux-aws, linux-fips, linux-kvm and linux-lts-xenial packages. For Ubuntu 16.04 LTS, the fixed versions include linux-image-generic 4.4.0.288.294, linux-image-aws 4.4.0.1197.201, linux-image-kvm 4.4.0.1160.157 and linux-image-fips 4.4.0.1129.131. For Ubuntu 14.04 LTS, the fixed versions are linux-image-generic-lts-xenial 4.4.0.288.32214.04.1, linux-image-aws 4.4.0.1159.156 and linux-image-lowlatency-lts-xenial 4.4.0.288.32214.04.1.
It's worth noting that, for both releases, most of the packages are only available via Ubuntu Pro, with the fix for aws, fips, kvm and the generic/lowlatency kernels covered by the Legacy Support add-on, since both versions have been out of standard support for some time.
What to do
After performing the standard system update, you need to reboot the machine for the changes to take effect. The advisory also flags an unavoidable ABI change: anyone with third-party kernel modules installed must recompile and reinstall them. If the standard kernel metapackages (linux-generic, linux-generic-lts-RELEASE, linux-virtual) haven't been manually removed, the system update will handle this automatically.
For the complete technical details and the exact list of versions for each kernel variant, refer to the advisory text at ubuntu.com/security/notices/USN-8864-1.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.