|
|
Log in / Subscribe / Register

Ubuntu alert USN-8391-1 (linux-raspi, linux-raspi-5.4)

From:  Rodrigo Figueiredo Zaiden via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8391-1] Linux kernel (Raspberry Pi) vulnerabilities
Date:  Thu, 04 Jun 2026 18:38:57 -0300
Message-ID:  <3681ce2f-ca34-4c49-8385-009fad9f273e@canonical.com>
Cc:  Rodrigo Figueiredo Zaiden <rodrigo.zaiden@canonical.com>

========================================================================== Ubuntu Security Notice USN-8391-1 June 04, 2026 linux-raspi, linux-raspi-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi: Linux kernel for Raspberry Pi systems - linux-raspi-5.4: Linux kernel for Raspberry Pi systems Details: It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Network drivers; - NVME drivers; - IPv4 networking; - Packet sockets; - RDS protocol; - TLS protocol; (CVE-2024-50304, CVE-2026-23112, CVE-2026-23209, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-43494, CVE-2026-46028) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1143-raspi 5.4.0-1143.156 Available with Ubuntu Pro linux-image-raspi 5.4.0.1143.174 Available with Ubuntu Pro linux-image-raspi-5.4 5.4.0.1143.174 Available with Ubuntu Pro linux-image-raspi2 5.4.0.1143.174 Available with Ubuntu Pro Ubuntu 18.04 LTS linux-image-5.4.0-1143-raspi 5.4.0-1143.156~18.04.1 Available with Ubuntu Pro linux-image-raspi-5.4 5.4.0.1143.156~18.04.1 Available with Ubuntu Pro linux-image-raspi-hwe-18.04 5.4.0.1143.156~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8391-1 CVE-2024-50304, CVE-2026-23112, CVE-2026-23209, CVE-2026-31431, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-43284, CVE-2026-43494, CVE-2026-43500, CVE-2026-46028


Attachment: OpenPGP_signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmoh8HEFAwAAAAAACgkQZ0GeRcM5nt3U XQf/Vp+a8B17Oaofds/9AA510GN3Q89PLUGr0JdZgLDuaSVUP9emUzhM8t/izpHYFUh7zEeEBg3l jrQh6wQrP9nQDlCZhbFhseBqDVJOKAxT9QQVImlPvO0k15z9WZ50uD8OfehFN3TBO299JLfUUDRp i4hK2pHGT8ySDKMgjcNP/LTe/8uxhRzDdt60anSexs3wQjzJFJRvXapbvS8PbGBjwFPinZH1nEZb nXXyC2/B8sa+VpyIIJpo2oG8VoG6i25KyvLsfwTU32sgqhKSY5ulT1PAQ2PxkhDQcGIJkUW+KiRb 1fTwRh7Z5ZWmklNiKFKsVnPD9vOdV+KIyFyCHBzm6A== =Ykgt -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds