USN-8905-1: Linux kernel flaws on GCP, update and reboot your instances
Ubuntu fixes dozens of vulnerabilities in the linux-gcp kernel for 22.04 and 24.04 LTS. A reboot and recompilation of third-party kernel modules are required.
UptimeMag editorial team · 8 October 2026 · 1 min read

Ubuntu published the USN-8905-1 security notice on 8 October 2026, fixing several dozen vulnerabilities in the Linux kernel used on Google Cloud Platform (GCP) instances. This affects anyone running VMs on GCP with Ubuntu 22.04 LTS or 24.04 LTS: an attacker could exploit these flaws to compromise the system, according to the official notice.
Affected packages
The packages involved are linux-gcp-6.8 and linux-gcp-fips (the latter for FIPS-certified systems). The fixes touch a very wide range of subsystems: ARM32, ARM64, MIPS and x86 architectures, GPU drivers, HID, I2C, InfiniBand, networking (including Mellanox, Microsoft Azure Network Adapter and Ethernet bonding), Ext4 and FUSE file systems, Bluetooth, netfilter, IPv4/IPv6, KVM and many others, for a total of over 230 CVEs referenced in the notice.
Fixed versions
| Ubuntu | Package | Version |
|---|---|---|
| 24.04 LTS (noble) | linux-image-6.8.0-1070-gcp-fips | 6.8.0-1070.78+fips1 |
| 24.04 LTS (noble) | linux-image-gcp-fips | 6.8.0-1070.78+fips1 |
| 24.04 LTS (noble) | linux-image-gcp-fips-6.8 | 6.8.0-1070.78+fips1 |
| 22.04 LTS (jammy) | linux-image-6.8.0-1070-gcp | 6.8.0-1070.78~22.04.1 |
| 22.04 LTS (jammy) | linux-image-6.8.0-1070-gcp-64k | 6.8.0-1070.78~22.04.1 |
| 22.04 LTS (jammy) | linux-image-gcp / gcp-6.8 / gcp-64k / gcp-64k-6.8 | 6.8.0-1070.78~22.04.1 |
FIPS packages are only available via Ubuntu Pro.
What to do on your instances
After the standard system update, you need to reboot the machine to apply all the changes. The notice flags an unavoidable ABI change: anyone with manually installed third-party kernel modules must recompile and reinstall them. Anyone who hasn't removed the standard metapackages (e.g. linux-generic, linux-virtual) gets this step automatically with a normal system update.
Source: Ubuntu Security Notices, USN-8905-1.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.