CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8662-2: Linux kernel (FIPS) vulnerabilities

unknownpublic exploitCVE-2026-31405CVE-2026-31414CVE-2026-31448CVE-2026-31649CVE-2026-43198CVE-2026-43493
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - STMicroelectronics network drivers; - Network drivers; - Ext4 file system; - IPv4 networking; - TCP network protocol; - Locking primitives; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53006, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

CSIRTS triage

What
Multiple vulnerabilities in kernel subsystems including x86, cryptographic API, network drivers, and protocol handlers.
Who is affected
Systems running FIPS-enabled Linux kernel versions affected by the listed CVEs.
Urgency
Moderate; multiple subsystems patched but no public exploit reported; kernel vulnerabilities can be critical depending on specific flaw.
Action
Apply kernel security update USN-8662-2 from Ubuntu or equivalent from your distribution.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Linux kernel

Get an email when a new Linux kernel advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8662-2

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-31405coverage & exploitation statusNVD · CVE.org
CVE-2026-31414coverage & exploitation statusNVD · CVE.org
CVE-2026-31448coverage & exploitation statusNVD · CVE.org
CVE-2026-31649coverage & exploitation statusNVD · CVE.org
CVE-2026-43198coverage & exploitation statusNVD · CVE.org
CVE-2026-43493coverage & exploitation statusNVD · CVE.org
CVE-2026-43499coverage & exploitation statusNVD · CVE.org
CVE-2026-46266coverage & exploitation statusNVD · CVE.org
CVE-2026-52955coverage & exploitation statusNVD · CVE.org
CVE-2026-52982coverage & exploitation statusNVD · CVE.org
CVE-2026-52986coverage & exploitation statusNVD · CVE.org
CVE-2026-53006coverage & exploitation statusNVD · CVE.org
CVE-2026-53176coverage & exploitation statusNVD · CVE.org
CVE-2026-53225coverage & exploitation statusNVD · CVE.org
CVE-2026-53228coverage & exploitation statusNVD · CVE.org
CVE-2026-53359coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices