USN-7864-1: Linux kernel (GCP and GKE) vulnerabilities
USN-7864-1: Linux kernel (GCP and GKE) vulnerabilities
Publication date: 7 November 2025
Overview:Several security issues were fixed in the Linux kernel.
Packages
linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems
linux-gcp-6.8 - Linux kernel for Google Cloud Platform (GCP) systems
linux-gke - Linux kernel for Google Container Engine (GKE) systems
Details
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- HSI subsystem;
- I2C subsystem;
- Bluetooth subsystem;
- Timer subsystem
Update instructions
The problem can be corrected by updating your system to the following package versions:
24.04 LTS noble
- linux-image-6.8.0-1039-gke – 6.8.0-1039.44
- linux-image-6.8.0-1039-gke-64k – 6.8.0-1039.44
- linux-image-6.8.0-1043-gcp – 6.8.0-1043.46
- linux-image-6.8.0-1043-gcp-64k – 6.8.0-1043.46
- linux-image-gcp-6.8 – 6.8.0-1043.46
- linux-image-gcp-64k-6.8 – 6.8.0-1043.46
- linux-image-gcp-64k-lts-24.04 – 6.8.0-1043.46
- linux-image-gcp-lts-24.04 – 6.8.0-1043.46
- linux-image-gke – 6.8.0-1039.44
- linux-image-gke-6.8 – 6.8.0-1039.44
- linux-image-gke-64k – 6.8.0-1039.44
- linux-image-gke-64k-6.8 – 6.8.0-1039.44
22.04 LTS jammy
- linux-image-6.8.0-1043-gcp – 6.8.0-1043.46~22.04.1
- linux-image-6.8.0-1043-gcp-64k – 6.8.0-1043.46~22.04.1
- linux-image-gcp – 6.8.0-1043.46~22.04.1
- linux-image-gcp-6.8 – 6.8.0-1043.46~22.04.1
- linux-image-gcp-64k – 6.8.0-1043.46~22.04.1
- linux-image-gcp-64k-6.8 – 6.8.0-1043.46~22.04.1

