USN-8865-1: four CVEs in EDK II, OVMF patch for all Ubuntu LTS releases
Canonical has published USN-8865-1: four vulnerabilities in EDK II (UEFI firmware for VMs) fixed with new versions of ovmf and qemu-efi across all Ubuntu LTS releases.
UptimeMag editorial team · 5 October 2026 · 2 min read

On 5 October 2026 Canonical published advisory USN-8865-1, which fixes four vulnerabilities in EDK II, the UEFI firmware used by virtual machines (the edk2 package, which provides ovmf and qemu-efi/qemu-efi-aarch64). For anyone running KVM/QEMU hosts with UEFI boot, this is the firmware sitting behind every modern VM: a flaw here has a direct impact on VM-to-host isolation.
The vulnerabilities
All the flaws stem from the OpenSSL library embedded in EDK II:
- CVE-2026-63072: incorrect handling of CMS key unwrapping, potentially leading to a heap buffer overflow and denial of service. Affects 18.04, 20.04, 22.04, 24.04 and 26.04 LTS.
- CVE-2026-63076: incorrect verification of CMP protection, potentially leading to denial of service. Affects only 24.04 and 26.04 LTS.
- CVE-2026-54874: incorrect buffering of DTLS records, allowing a remote attacker to cause excessive memory consumption.
- CVE-2026-75803: incorrect verification of AEAD tags, allowing an attacker to get forged messages accepted. Affects only 24.04 and 26.04 LTS.
Fixed versions
| Release | Package | Version |
|---|---|---|
| 26.04 LTS (resolute) | ovmf / qemu-efi-aarch64 | 2025.11-3ubuntu7.3 |
| 24.04 LTS (noble) | ovmf / qemu-efi-aarch64 | 2024.02-2ubuntu0.10 |
| 22.04 LTS (jammy) | ovmf / qemu-efi | 2022.02-3ubuntu0.22.04.7 |
| 20.04 LTS (focal) | ovmf / qemu-efi | 0~20191122.bd85bf54-2ubuntu3.6+esm1 (requires Ubuntu Pro) |
| 18.04 LTS (bionic) | ovmf / qemu-efi | 0~20180205.c0d9813c-2ubuntu0.3+esm3 (requires Ubuntu Pro via ESM Apps) |
| 16.04 LTS (xenial) | ovmf / qemu-efi | 0~20160408.ffea0a2c-2ubuntu0.2+esm4 |
For 18.04 and 20.04 LTS the fix is only available with an Ubuntu Pro subscription; for 16.04 LTS it isn't specified whether ESM is required. For 18.04 LTS, Canonical notes that "a community fix might become publicly available in the future".
What to do
A standard system update (apt update && apt upgrade) will install the fixed packages. After updating ovmf/qemu-efi, virtual machines need to be restarted to load the new UEFI firmware: rebooting the host alone isn't enough if the VMs remain running with the old firmware still in memory.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.