News

USN-8865-1: four CVEs in EDK II, OVMF patch for all Ubuntu LTS releases

Canonical has published USN-8865-1: four vulnerabilities in EDK II (UEFI firmware for VMs) fixed with new versions of ovmf and qemu-efi across all Ubuntu LTS releases.

UptimeMag editorial team · 5 October 2026 · 2 min read

USN-8865-1: quattro CVE in EDK II, patch OVMF per tutte le Ubuntu LTS

On 5 October 2026 Canonical published advisory USN-8865-1, which fixes four vulnerabilities in EDK II, the UEFI firmware used by virtual machines (the edk2 package, which provides ovmf and qemu-efi/qemu-efi-aarch64). For anyone running KVM/QEMU hosts with UEFI boot, this is the firmware sitting behind every modern VM: a flaw here has a direct impact on VM-to-host isolation.

The vulnerabilities

All the flaws stem from the OpenSSL library embedded in EDK II:

  • CVE-2026-63072: incorrect handling of CMS key unwrapping, potentially leading to a heap buffer overflow and denial of service. Affects 18.04, 20.04, 22.04, 24.04 and 26.04 LTS.
  • CVE-2026-63076: incorrect verification of CMP protection, potentially leading to denial of service. Affects only 24.04 and 26.04 LTS.
  • CVE-2026-54874: incorrect buffering of DTLS records, allowing a remote attacker to cause excessive memory consumption.
  • CVE-2026-75803: incorrect verification of AEAD tags, allowing an attacker to get forged messages accepted. Affects only 24.04 and 26.04 LTS.

Fixed versions

Release Package Version
26.04 LTS (resolute) ovmf / qemu-efi-aarch64 2025.11-3ubuntu7.3
24.04 LTS (noble) ovmf / qemu-efi-aarch64 2024.02-2ubuntu0.10
22.04 LTS (jammy) ovmf / qemu-efi 2022.02-3ubuntu0.22.04.7
20.04 LTS (focal) ovmf / qemu-efi 0~20191122.bd85bf54-2ubuntu3.6+esm1 (requires Ubuntu Pro)
18.04 LTS (bionic) ovmf / qemu-efi 0~20180205.c0d9813c-2ubuntu0.3+esm3 (requires Ubuntu Pro via ESM Apps)
16.04 LTS (xenial) ovmf / qemu-efi 0~20160408.ffea0a2c-2ubuntu0.2+esm4

For 18.04 and 20.04 LTS the fix is only available with an Ubuntu Pro subscription; for 16.04 LTS it isn't specified whether ESM is required. For 18.04 LTS, Canonical notes that "a community fix might become publicly available in the future".

What to do

A standard system update (apt update && apt upgrade) will install the fixed packages. After updating ovmf/qemu-efi, virtual machines need to be restarted to load the new UEFI firmware: rebooting the host alone isn't enough if the VMs remain running with the old firmware still in memory.

Source: USN-8865-1 on ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.