CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8665-1: Linux kernel (Raspberry Pi) vulnerabilities

unknownCVE-2025-54505CVE-2025-54518CVE-2025-62626CVE-2025-21709CVE-2025-22116CVE-2025-38426
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. (CVE-2025-62626) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - Clock framework and drivers; - Data acquisition framework and drivers; - Counter interface drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - DMA engine subsystem; - EDAC drivers; - EFI core; - GPU drivers; - Greybus drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IRQ chip drivers; - LED subsystem; - Mailbox framework; - Mu

CSIRTS triage

What
Microarchitectural vulnerabilities in AMD processors and Linux kernel flaws affecting floating-point divider, operation cache isolation, and RDSEED entropy handling.
Who is affected
Raspberry Pi systems and those running affected AMD processors with vulnerable Linux kernels.
Urgency
Moderate; side-channel and privilege escalation vectors, mostly local exploitation required.
Action
Apply USN-8665-1 kernel security update for Raspberry Pi.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Linux kernel (Raspberry Pi)

Get an email when a new Linux kernel (Raspberry Pi) advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8665-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-54505coverage & exploitation statusNVD · CVE.org
CVE-2025-54518coverage & exploitation statusNVD · CVE.org
CVE-2025-62626coverage & exploitation statusNVD · CVE.org
CVE-2025-21709coverage & exploitation statusNVD · CVE.org
CVE-2025-22116coverage & exploitation statusNVD · CVE.org
CVE-2025-38426coverage & exploitation statusNVD · CVE.org
CVE-2025-39764coverage & exploitation statusNVD · CVE.org
CVE-2025-40135coverage & exploitation statusNVD · CVE.org
CVE-2025-40150coverage & exploitation statusNVD · CVE.org
CVE-2025-68175coverage & exploitation statusNVD · CVE.org
CVE-2025-68239coverage & exploitation statusNVD · CVE.org
CVE-2025-68334coverage & exploitation statusNVD · CVE.org
CVE-2025-68736coverage & exploitation statusNVD · CVE.org
CVE-2025-71152coverage & exploitation statusNVD · CVE.org
CVE-2025-71161coverage & exploitation statusNVD · CVE.org
CVE-2025-71203coverage & exploitation statusNVD · CVE.org
CVE-2025-71221coverage & exploitation statusNVD · CVE.org
CVE-2025-71269coverage & exploitation statusNVD · CVE.org
CVE-2025-71287coverage & exploitation statusNVD · CVE.org
CVE-2025-71288coverage & exploitation statusNVD · CVE.org
CVE-2026-22981coverage & exploitation statusNVD · CVE.org
CVE-2026-22985coverage & exploitation statusNVD · CVE.org
CVE-2026-22993coverage & exploitation statusNVD · CVE.org
CVE-2026-23004coverage & exploitation statusNVD · CVE.org
CVE-2026-23066coverage & exploitation statusNVD · CVE.org
CVE-2026-23104coverage & exploitation statusNVD · CVE.org
CVE-2026-23118coverage & exploitation statusNVD · CVE.org
CVE-2026-23138coverage & exploitation statusNVD · CVE.org
CVE-2026-23154coverage & exploitation statusNVD · CVE.org
CVE-2026-23157coverage & exploitation statusNVD · CVE.org
CVE-2026-23171coverage & exploitation statusNVD · CVE.org
CVE-2026-23207coverage & exploitation statusNVD · CVE.org
CVE-2026-23226coverage & exploitation statusNVD · CVE.org
CVE-2026-23227coverage & exploitation statusNVD · CVE.org
CVE-2026-23244coverage & exploitation statusNVD · CVE.org
CVE-2026-23245coverage & exploitation statusNVD · CVE.org
CVE-2026-23246coverage & exploitation statusNVD · CVE.org
CVE-2026-23253coverage & exploitation statusNVD · CVE.org
CVE-2026-23255coverage & exploitation statusNVD · CVE.org
CVE-2026-23270coverage & exploitation statusNVD · CVE.org
CVE-2026-23271coverage & exploitation statusNVD · CVE.org
CVE-2026-23276coverage & exploitation statusNVD · CVE.org
CVE-2026-23277coverage & exploitation statusNVD · CVE.org
CVE-2026-23279coverage & exploitation statusNVD · CVE.org
CVE-2026-23281coverage & exploitation statusNVD · CVE.org
CVE-2026-23284coverage & exploitation statusNVD · CVE.org
CVE-2026-23285coverage & exploitation statusNVD · CVE.org
CVE-2026-23286coverage & exploitation statusNVD · CVE.org

+864 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices