========================================================================== Ubuntu Security Notice USN-8281-1 May 19, 2026
linux, linux-aws, linux-aws-fips, linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-aws-fips: Linux kernel for Amazon Web Services (AWS) systems with FIPS - linux-fips: Linux kernel with FIPS - linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems- linux-gcp-fips: Linux kernel for Google Cloud Platform (GCP) systems with FIPS
- linux-kvm: Linux kernel for cloud environments
- linux-oracle: Linux kernel for Oracle Cloud systems
Details:
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- Packet sockets;
(CVE-2026-31504, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
linux-image-4.15.0-1147-fips 4.15.0-1147.159
Available with Ubuntu Pro
linux-image-4.15.0-1154-oracle 4.15.0-1154.165
Available with Ubuntu Pro
linux-image-4.15.0-1174-kvm 4.15.0-1174.179
Available with Ubuntu Pro
linux-image-4.15.0-1185-gcp 4.15.0-1185.202
Available with Ubuntu Pro
linux-image-4.15.0-1192-aws 4.15.0-1192.205
Available with Ubuntu Pro
linux-image-4.15.0-2093-gcp-fips 4.15.0-2093.99
Available with Ubuntu Pro
linux-image-4.15.0-2130-aws-fips 4.15.0-2130.136
Available with Ubuntu Pro
linux-image-4.15.0-250-generic 4.15.0-250.262
Available with Ubuntu Pro
linux-image-4.15.0-250-lowlatency 4.15.0-250.262
Available with Ubuntu Pro
linux-image-aws-4.15 4.15.0.1192.190
Available with Ubuntu Pro
linux-image-aws-fips 4.15.0.2130.124
Available with Ubuntu Pro
linux-image-aws-fips-4.15 4.15.0.2130.124
Available with Ubuntu Pro
linux-image-aws-lts-18.04 4.15.0.1192.190
Available with Ubuntu Pro
linux-image-fips 4.15.0.1147.144
Available with Ubuntu Pro
linux-image-gcp-4.15 4.15.0.1185.198
Available with Ubuntu Pro
linux-image-gcp-fips 4.15.0.2093.91
Available with Ubuntu Pro
linux-image-gcp-fips-4.15 4.15.0.2093.91
Available with Ubuntu Pro
linux-image-gcp-lts-18.04 4.15.0.1185.198
Available with Ubuntu Pro
linux-image-generic 4.15.0.250.234
Available with Ubuntu Pro
linux-image-kvm 4.15.0.1174.165
Available with Ubuntu Pro
linux-image-lowlatency 4.15.0.250.234
Available with Ubuntu Pro
linux-image-oracle-4.15 4.15.0.1154.159
Available with Ubuntu Pro
linux-image-oracle-lts-18.04 4.15.0.1154.159
Available with Ubuntu Pro
linux-image-virtual 4.15.0.250.234
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-8281-1
CVE-2026-31431, CVE-2026-31504, CVE-2026-43033, CVE-2026-43077,
CVE-2026-43078
OpenPGP_signature.asc
Description: OpenPGP digital signature
