USN-8871-1: Ubuntu kernel patch for Raspberry Pi, requires reboot and module recompilation
Canonical fixes around twenty CVEs in the linux-raspi kernel for Ubuntu 22.04 LTS. A reboot and recompilation of third-party modules are required.
UptimeMag editorial team · 5 October 2026 · 2 min read

Canonical published the security notice USN-8871-1 on 5 October 2026, fixing a series of vulnerabilities in the Linux kernel for Raspberry Pi systems on Ubuntu 22.04 LTS (Jammy), package linux-raspi. For anyone managing fleets of Raspberry Pi devices in production — IoT gateways, edge nodes, small servers — this is an update to schedule straight away, not to put off: among the flaws fixed is one that touches the hardware itself, not just software.
The most serious flaw: TLB invalidation on Arm
The most significant flaw is CVE-2025-10263: certain Arm processors may complete a broadcast TLB (translation lookaside buffer) invalidation before writes to memory made via that translation have been globally observed by the system. In practice, a local attacker could write to memory after the permission had already been revoked, bypassing memory protections or achieving privilege escalation. According to the Ubuntu advisory, exploitation requires local access to the machine.
The other CVEs fixed
The advisory lists over twenty additional CVEs, covering: the ARM64 architecture, InfiniBand drivers, network drivers, the TCM subsystem, the exFAT file system, the NFS client and server, the B.A.T.M.A.N. mesh networking protocol, IPv4 and IPv6 networking, Netfilter, and the RDS protocol. The full list of CVE references is available on the official advisory page.
Fixed packages and versions
| Package | Version |
|---|---|
| linux-image-5.15.0-1110-raspi | 5.15.0-1110.113 |
| linux-image-raspi | 5.15.0.1110.108 |
| linux-image-raspi-5.15 | 5.15.0.1110.108 |
| linux-image-raspi-nolpae | 5.15.0.1110.108 |
What to do
After the standard system update (apt update && apt upgrade), you need to reboot the machine for the changes to take effect. Canonical flags a particular point of attention: due to an unavoidable ABI change, the kernel has a new version number, so all third-party kernel modules must be recompiled and reinstalled. If you haven't manually removed the standard kernel metapackages (e.g. linux-generic, linux-raspi), a standard system update will carry out this step automatically.
The full advisory, with the complete list of CVEs, is published on the official Ubuntu Security Notices website.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.