USN-8888-2: Linux kernel flaws on Azure put SEV-SNP guest integrity at risk
Canonical has published USN-8888-2: multiple flaws in the Linux kernel for Azure instances, one of which compromises SEV-SNP guest integrity. Updating and rebooting is required.
UptimeMag editorial team · 8 October 2026 · 1 min read

Canonical has published security notice USN-8888-2, which fixes several vulnerabilities in the Linux kernel for Ubuntu instances on Microsoft Azure. This affects anyone running Ubuntu-based Azure VMs: the kernel package needs to be updated and the instance rebooted for the patches to take effect.
The most serious flaw: CVE-2023-20585
According to the official advisory (source: ubuntu.com/security/notices/USN-8888-2), on certain AMD processors the Reverse Map Table (RMP) checks were not being performed correctly when the IOMMU accessed specific host buffers. A local attacker with hypervisor access could exploit this flaw to trigger an out-of-bounds condition and compromise the memory integrity of guests protected with SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging).
Anyone running Azure instances with SEV-SNP protection to isolate sensitive workloads should treat this CVE as a priority: among those listed in the advisory, it is the only one that directly affects the confidential computing security model.
The other fixes
The advisory lists further security issues in the Linux kernel, generically described as exploitable by an attacker to compromise the system. The subsystems involved are:
- ARM64 architecture;
- NVDIMM (Non-Volatile Memory Device) driver;
- Handshake API;
- ARM32 architecture (the source text appears to be truncated at this point).
The specific CVE numbers for these additional fixes, along with further technical details, are not given in the available text: the original advisory should be consulted for the full list.
What to do
As with any kernel-related USN, the update requires the instance to be rebooted to take effect: running apt upgrade alone is not enough to load the new kernel into memory. On managed Azure images, check the installed kernel package version after updating and schedule a maintenance window for the reboot, especially if you're running SEV-SNP guests in production.
Official reference: USN-8888-2 on ubuntu.com.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.