News

USN-8877-1: dozens of linux-gcp kernel flaws, reboot and module rebuild required

Ubuntu fixes dozens of CVEs in the Google Cloud Platform kernel for 22.04 LTS. ABI bump: a reboot and rebuilding of third-party modules is required.

UptimeMag editorial team · 6 October 2026 · 1 min read

USN-8877-1: decine di falle nel kernel linux-gcp, reboot e ricompilazione moduli

Ubuntu published advisory USN-8877-1 on 6 October 2026, fixing dozens of vulnerabilities in the Linux kernel for Google Cloud Platform. It affects anyone running Ubuntu 22.04 LTS (jammy) instances on GCP with the linux-gcp and linux-gcp-fips packages. If you have VMs on GCP running this distribution, you need to plan for a reboot, not just a live update.

What it fixes

The advisory explicitly cites CVE-2022-3114: a bug in the i.MX clock driver that failed to properly handle memory allocation failures, resulting in a null pointer dereference. A local attacker could exploit this to crash the system (denial of service).

On top of this, there are dozens of other 2026 CVEs affecting widely used subsystems: filesystems (Btrfs, XFS, NFS, exFAT, F2FS), the networking stack (IPv4/IPv6, Netfilter, Bluetooth, SCTP), USB drivers, GPU, KVM, io_uring and more, according to the list published by Ubuntu in the advisory.

Fixed versions

Package Fixed version
linux-image-5.15.0-1118-gcp 5.15.0-1118.128
linux-image-5.15.0-1118-gcp-fips 5.15.0-1118.128+fips1 (requires Ubuntu Pro)
linux-image-gcp-5.15 5.15.0.1118.115
linux-image-gcp-lts-22.04 5.15.0.1118.115

Watch out for the ABI bump

Ubuntu notes that this update involves an ABI change: the kernel receives a new version number. This means that any manually installed third-party kernel module (proprietary drivers, custom modules) needs to be rebuilt and reinstalled. If you haven't manually removed the standard kernel metapackage (linux-generic or similar), a normal system update will handle this step automatically.

After the standard update, a reboot is required to apply the changes. For those with an Ubuntu Pro subscription, the FIPS variant receives the same fix while retaining FIPS-140 certification.

For full details, the complete list of fixed CVEs and update instructions, refer to the official USN-8877-1 advisory at ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.