linux, linux-aws, linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HSI subsystem; - I3C subsystem; - SMB network file system; - Padata parallel execution mechanism; - Timer subsystem; - Networking core; (CVE-2023-52854, CVE-2024-35867, CVE-2024-50061, CVE-2024-56664, CVE-2025-21727, CVE-2025-37838, CVE-2025-38352)
02 / AFFECTED SOFTWARE
Affected packages
100 explicit affected versions
102 explicit affected versions
112 explicit affected versions
70 explicit affected versions
101 explicit affected versions
93 explicit affected versions
123 explicit affected versions
114 explicit affected versions
115 explicit affected versions
80 explicit affected versions
110 explicit affected versions
112 explicit affected versions
98 explicit affected versions
47 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HSI subsystem; - I3C subsystem; - SMB network file system; - Padata parallel execution mechanism; - Timer subsystem; - Networking core; (CVE-2023-52854, CVE-2024-35867, CVE-2024-50061, CVE-2024-56664, CVE-2025-21727, CVE-2025-37838, CVE-2025-38352)
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2023-52854
- https://ubuntu.com/security/CVE-2024-35867
- https://ubuntu.com/security/CVE-2024-50061
- https://ubuntu.com/security/CVE-2024-56664
- https://ubuntu.com/security/CVE-2025-21727
- https://ubuntu.com/security/CVE-2025-37838
- https://ubuntu.com/security/CVE-2025-38352
- https://ubuntu.com/security/CVE-2025-40300
- https://ubuntu.com/security/notices/USN-7874-1