Update

USN-7864-1: Linux kernel (GCP and GKE) vulnerabilities

USN-7864-1: Linux kernel (GCP and GKE) vulnerabilities

Publication date: 7 November 2025
Overview:Several security issues were fixed in the Linux kernel.

Packages
linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems
linux-gcp-6.8 - Linux kernel for Google Cloud Platform (GCP) systems
linux-gke - Linux kernel for Google Container Engine (GKE) systems

Details
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • HSI subsystem;
  • I2C subsystem;
  • Bluetooth subsystem;
  • Timer subsystem

Update instructions
The problem can be corrected by updating your system to the following package versions:

24.04 LTS noble

  • linux-image-6.8.0-1039-gke – 6.8.0-1039.44
  • linux-image-6.8.0-1039-gke-64k – 6.8.0-1039.44
  • linux-image-6.8.0-1043-gcp – 6.8.0-1043.46
  • linux-image-6.8.0-1043-gcp-64k – 6.8.0-1043.46
  • linux-image-gcp-6.8 – 6.8.0-1043.46
  • linux-image-gcp-64k-6.8 – 6.8.0-1043.46
  • linux-image-gcp-64k-lts-24.04 – 6.8.0-1043.46
  • linux-image-gcp-lts-24.04 – 6.8.0-1043.46
  • linux-image-gke – 6.8.0-1039.44
  • linux-image-gke-6.8 – 6.8.0-1039.44
  • linux-image-gke-64k – 6.8.0-1039.44
  • linux-image-gke-64k-6.8 – 6.8.0-1039.44

22.04 LTS jammy

  • linux-image-6.8.0-1043-gcp – 6.8.0-1043.46~22.04.1
  • linux-image-6.8.0-1043-gcp-64k – 6.8.0-1043.46~22.04.1
  • linux-image-gcp – 6.8.0-1043.46~22.04.1
  • linux-image-gcp-6.8 – 6.8.0-1043.46~22.04.1
  • linux-image-gcp-64k – 6.8.0-1043.46~22.04.1
  • linux-image-gcp-64k-6.8 – 6.8.0-1043.46~22.04.1
The manufacturer Canonical has not yet set up its devicebase profile. Content such as updates, compatibilities and support may only be maintained with a delay.
Receive Important Update Messages Stay tuned for upcoming Canonical updates

Was the content helpful to you?

Advertisement Advertise here?
Udemy IT certification ad