USN-7379-1: Linux kernel vulnerabilities

Publication date

27 March 2025

Overview

Several security issues were fixed in the Linux kernel.


Packages

  • linux - Linux kernel
  • linux-aws - Linux kernel for Amazon Web Services (AWS) systems
  • linux-azure - Linux kernel for Microsoft Azure Cloud systems
  • linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems
  • linux-hwe-6.11 - Linux hardware enablement (HWE) kernel
  • linux-oracle - Linux kernel for Oracle Cloud systems
  • linux-realtime - Linux kernel for Real-time systems

Details

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • ARM64 architecture;
  • MIPS architecture;
  • PowerPC architecture;
  • RISC-V architecture;
  • S390 architecture;
  • x86 architecture;
  • Block layer subsystem;
  • Compute Acceleration Framework;
  • ACPI drivers;
  • Drivers core;
  • Ublk userspace block driver;
  • Virtio block driver;
  • Bluetooth drivers;
  • Buffer Sharing and Synchronization framework;
  • DMA engine subsystem;
  • EFI core;
  • GPIO subsystem;
  • GPU drivers;
  • HID subsystem;
  • Microsoft Hyper-V drivers;
  • Hardware monitoring drivers;
  • I3C subsystem;
  • IIO ADC drivers;
  • IIO subsystem;
  • InfiniBand drivers;
  • IOMMU subsystem;
  • LED...

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • ARM64 architecture;
  • MIPS architecture;
  • PowerPC architecture;
  • RISC-V architecture;
  • S390 architecture;
  • x86 architecture;
  • Block layer subsystem;
  • Compute Acceleration Framework;
  • ACPI drivers;
  • Drivers core;
  • Ublk userspace block driver;
  • Virtio block driver;
  • Bluetooth drivers;
  • Buffer Sharing and Synchronization framework;
  • DMA engine subsystem;
  • EFI core;
  • GPIO subsystem;
  • GPU drivers;
  • HID subsystem;
  • Microsoft Hyper-V drivers;
  • Hardware monitoring drivers;
  • I3C subsystem;
  • IIO ADC drivers;
  • IIO subsystem;
  • InfiniBand drivers;
  • IOMMU subsystem;
  • LED subsystem;
  • Multiple devices driver;
  • Media drivers;
  • Microchip PCI driver;
  • MTD block device drivers;
  • Network drivers;
  • Mellanox network drivers;
  • STMicroelectronics network drivers;
  • NVME drivers;
  • PCI subsystem;
  • PHY drivers;
  • Pin controllers subsystem;
  • x86 platform drivers;
  • i.MX PM domains;
  • Power supply drivers;
  • Voltage and Current Regulator drivers;
  • SCSI subsystem;
  • i.MX SoC drivers;
  • SPI subsystem;
  • UFS subsystem;
  • USB Gadget drivers;
  • TDX Guest driver;
  • AFS file system;
  • BTRFS file system;
  • Ceph distributed file system;
  • File systems infrastructure;
  • F2FS file system;
  • JFFS2 file system;
  • JFS file system;
  • Network file systems library;
  • Network file system (NFS) server daemon;
  • NILFS2 file system;
  • File system notification infrastructure;
  • Overlay file system;
  • Diskquota system;
  • SMB network file system;
  • DRM display driver;
  • BPF subsystem;
  • VLANs driver;
  • KASAN memory debugging framework;
  • Memory management;
  • StackDepot library;
  • Bluetooth subsystem;
  • LAPB network protocol;
  • Netfilter;
  • io_uring subsystem;
  • Control group (cgroup);
  • DMA mapping infrastructure;
  • KCSAN framework;
  • Scheduler infrastructure;
  • Seccomp subsystem;
  • Tracing infrastructure;
  • Workqueue subsystem;
  • KUnit library;
  • CAN network layer;
  • Networking core;
  • DCCP (Datagram Congestion Control Protocol);
  • HSR network protocol;
  • IEEE802154.4 network protocol;
  • IPv4 networking;
  • IPv6 networking;
  • MAC80211 subsystem;
  • Multipath TCP;
  • NET/ROM layer;
  • Packet sockets;
  • RDS protocol;
  • Network traffic control;
  • SCTP protocol;
  • SMC sockets;
  • TIPC protocol;
  • Wireless networking;
  • eXpress Data Path;
  • SELinux security module;
  • ALSA framework;
  • Intel ASoC drivers;
  • SOF drivers


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.10 oracular linux-image-6.11.0-1007-realtime –  6.11.0-1007.7
linux-image-6.11.0-1011-aws –  6.11.0-1011.12
linux-image-6.11.0-1011-gcp –  6.11.0-1011.11
linux-image-6.11.0-1011-gcp-64k –  6.11.0-1011.11
linux-image-6.11.0-1012-azure –  6.11.0-1012.12
linux-image-6.11.0-1012-azure-fde –  6.11.0-1012.12
linux-image-6.11.0-1013-oracle –  6.11.0-1013.14
linux-image-6.11.0-1013-oracle-64k –  6.11.0-1013.14
linux-image-6.11.0-21-generic –  6.11.0-21.21
linux-image-6.11.0-21-generic-64k –  6.11.0-21.21
linux-image-aws –  6.11.0-1011.12
linux-image-azure –  6.11.0-1012.12
linux-image-azure-fde –  6.11.0-1012.12
linux-image-gcp –  6.11.0-1011.11
linux-image-gcp-64k –  6.11.0-1011.11
linux-image-generic –  6.11.0-21.21
linux-image-generic-64k –  6.11.0-21.21
linux-image-generic-64k-hwe-24.04 –  6.11.0-21.21
linux-image-generic-hwe-24.04 –  6.11.0-21.21
linux-image-oem-24.04 –  6.11.0-21.21
linux-image-oem-24.04a –  6.11.0-21.21
linux-image-oracle –  6.11.0-1013.14
linux-image-oracle-64k –  6.11.0-1013.14
linux-image-realtime –  6.11.0-1007.7
linux-image-realtime-hwe-24.04 –  6.11.0-1007.7
linux-image-virtual –  6.11.0-21.21
linux-image-virtual-hwe-24.04 –  6.11.0-21.21
24.04 noble linux-image-6.11.0-21-generic –  6.11.0-21.21~24.04.1+1
linux-image-6.11.0-21-generic-64k –  6.11.0-21.21~24.04.1+1
linux-image-generic-64k-hwe-24.04 –  6.11.0-21.21~24.04.1
linux-image-generic-hwe-24.04 –  6.11.0-21.21~24.04.1
linux-image-virtual-hwe-24.04 –  6.11.0-21.21~24.04.1

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

References



Have additional questions?

Talk to a member of the team ›