{"id":"USN-8098-5","summary":"linux-iot, linux-kvm vulnerabilities","details":"Qualys discovered that several vulnerabilities existed in the AppArmor\nLinux kernel Security Module (LSM). An unprivileged local attacker could\nuse these issues to load, replace, and remove arbitrary AppArmor profiles\ncausing denial of service, exposure of sensitive information (kernel\nmemory), local privilege escalation, or possibly escape a container.\n(LP: #2143853)\n\nSeveral security issues were discovered in the Linux kernel.\nAn attacker could possibly use these to compromise the system.\nThis update corrects flaws in the following subsystems:\n  - x86 architecture;\n  - GPIO subsystem;\n  - GPU drivers;\n  - MMC subsystem;\n  - BTRFS file system;\n  - XFRM subsystem;\n  - IPv4 networking;\n  - IPv6 networking;\n  - MAC80211 subsystem;\n  - SMC sockets;\n(CVE-2021-47599, CVE-2022-48875, CVE-2022-49072, CVE-2022-49267,\nCVE-2024-49927, CVE-2024-56640, CVE-2025-21780, CVE-2025-40215)\n","modified":"2026-08-06T03:04:12.411948126Z","published":"2026-03-24T16:31:58Z","related":["UBUNTU-CVE-2021-47599","UBUNTU-CVE-2022-48875","UBUNTU-CVE-2022-49072","UBUNTU-CVE-2022-49267","UBUNTU-CVE-2024-49927","UBUNTU-CVE-2024-56640","UBUNTU-CVE-2025-21780","UBUNTU-CVE-2025-40215"],"upstream":["UBUNTU-CVE-2021-47599","UBUNTU-CVE-2022-48875","UBUNTU-CVE-2022-49072","UBUNTU-CVE-2022-49267","UBUNTU-CVE-2024-49927","UBUNTU-CVE-2024-56640","UBUNTU-CVE-2025-21780","UBUNTU-CVE-2025-40215"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8098-5"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-47599"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-48875"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-49072"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-49267"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-49927"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-56640"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-21780"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-40215"},{"type":"REPORT","url":"https://launchpad.net/bugs/2143853"}],"affected":[{"package":{"name":"linux-iot","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux-iot?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.0-1060.63"}]}],"versions":["5.4.0-1001.3","5.4.0-1004.6","5.4.0-1005.7","5.4.0-1006.8","5.4.0-1009.11","5.4.0-1010.12","5.4.0-1011.13","5.4.0-1012.14","5.4.0-1013.15","5.4.0-1014.16","5.4.0-1017.18","5.4.0-1018.19","5.4.0-1019.20","5.4.0-1021.22","5.4.0-1022.23","5.4.0-1023.24","5.4.0-1024.25","5.4.0-1025.26","5.4.0-1026.27","5.4.0-1028.29","5.4.0-1029.30","5.4.0-1030.31","5.4.0-1031.32","5.4.0-1032.33","5.4.0-1033.34","5.4.0-1034.35","5.4.0-1035.36","5.4.0-1036.37","5.4.0-1037.38","5.4.0-1038.39","5.4.0-1039.40","5.4.0-1040.41","5.4.0-1041.42","5.4.0-1042.43","5.4.0-1043.44","5.4.0-1044.45","5.4.0-1045.46","5.4.0-1048.51","5.4.0-1049.52","5.4.0-1051.54","5.4.0-1052.55","5.4.0-1053.56","5.4.0-1054.57","5.4.0-1055.58","5.4.0-1056.59","5.4.0-1057.60","5.4.0-1058.61"],"ecosystem_specific":{"binaries":[{"binary_version":"5.4.0-1060.63","binary_name":"linux-buildinfo-5.4.0-1060-iot"},{"binary_name":"linux-headers-5.4.0-1060-iot","binary_version":"5.4.0-1060.63"},{"binary_version":"5.4.0-1060.63","binary_name":"linux-image-unsigned-5.4.0-1060-iot"},{"binary_name":"linux-iot-headers-5.4.0-1060","binary_version":"5.4.0-1060.63"},{"binary_name":"linux-iot-tools-5.4.0-1060","binary_version":"5.4.0-1060.63"},{"binary_name":"linux-modules-5.4.0-1060-iot","binary_version":"5.4.0-1060.63"},{"binary_name":"linux-tools-5.4.0-1060-iot","binary_version":"5.4.0-1060.63"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"id":"CVE-2021-47599","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48875","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-49072"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-49267"},{"id":"CVE-2024-49927","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2024-56640"},{"id":"CVE-2025-21780","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}]},{"id":"CVE-2025-40215","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8098-5.json"}},{"package":{"name":"linux-kvm","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux-kvm?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.0-1143.152"}]}],"versions":["5.3.0-1003.3","5.3.0-1008.9","5.3.0-1009.10","5.4.0-1004.4","5.4.0-1006.6","5.4.0-1007.7","5.4.0-1008.8","5.4.0-1009.9","5.4.0-1011.11","5.4.0-1015.15","5.4.0-1018.18","5.4.0-1020.20","5.4.0-1021.21","5.4.0-1023.23","5.4.0-1024.24","5.4.0-1026.27","5.4.0-1028.29","5.4.0-1030.31","5.4.0-1031.32","5.4.0-1032.33","5.4.0-1033.34","5.4.0-1034.35","5.4.0-1036.37","5.4.0-1037.38","5.4.0-1038.39","5.4.0-1039.40","5.4.0-1040.41","5.4.0-1041.42","5.4.0-1044.46","5.4.0-1045.47","5.4.0-1046.48","5.4.0-1047.49","5.4.0-1048.50","5.4.0-1049.51","5.4.0-1050.52","5.4.0-1051.53","5.4.0-1053.55","5.4.0-1054.56","5.4.0-1055.57","5.4.0-1056.58","5.4.0-1058.61","5.4.0-1059.62","5.4.0-1061.64","5.4.0-1062.65","5.4.0-1063.66","5.4.0-1065.68","5.4.0-1068.72","5.4.0-1070.75","5.4.0-1071.76","5.4.0-1073.78","5.4.0-1074.79","5.4.0-1075.80","5.4.0-1076.81","5.4.0-1078.84","5.4.0-1079.85","5.4.0-1082.88","5.4.0-1083.89","5.4.0-1084.90","5.4.0-1086.92","5.4.0-1087.93","5.4.0-1088.94","5.4.0-1089.95","5.4.0-1090.96","5.4.0-1091.97","5.4.0-1092.98","5.4.0-1093.99","5.4.0-1094.100","5.4.0-1095.101","5.4.0-1096.102","5.4.0-1097.103","5.4.0-1098.104","5.4.0-1099.105","5.4.0-1100.106","5.4.0-1101.107","5.4.0-1102.108","5.4.0-1103.110","5.4.0-1104.111","5.4.0-1105.112","5.4.0-1106.113","5.4.0-1107.114","5.4.0-1108.115","5.4.0-1109.116","5.4.0-1110.117","5.4.0-1111.118","5.4.0-1112.119","5.4.0-1113.120","5.4.0-1114.121","5.4.0-1115.122","5.4.0-1116.123","5.4.0-1117.124","5.4.0-1118.125","5.4.0-1119.127","5.4.0-1120.128","5.4.0-1121.129","5.4.0-1122.130","5.4.0-1123.131","5.4.0-1124.132","5.4.0-1125.133","5.4.0-1126.134","5.4.0-1127.136","5.4.0-1129.138","5.4.0-1130.139","5.4.0-1131.140","5.4.0-1132.141","5.4.0-1133.142","5.4.0-1134.143","5.4.0-1135.144","5.4.0-1136.145","5.4.0-1137.146","5.4.0-1138.147","5.4.0-1139.148","5.4.0-1140.149","5.4.0-1141.150"],"ecosystem_specific":{"binaries":[{"binary_name":"linux-buildinfo-5.4.0-1143-kvm","binary_version":"5.4.0-1143.152"},{"binary_version":"5.4.0-1143.152","binary_name":"linux-headers-5.4.0-1143-kvm"},{"binary_name":"linux-image-unsigned-5.4.0-1143-kvm","binary_version":"5.4.0-1143.152"},{"binary_name":"linux-kvm-headers-5.4.0-1143","binary_version":"5.4.0-1143.152"},{"binary_name":"linux-kvm-tools-5.4.0-1143","binary_version":"5.4.0-1143.152"},{"binary_version":"5.4.0-1143.152","binary_name":"linux-modules-5.4.0-1143-kvm"},{"binary_name":"linux-tools-5.4.0-1143-kvm","binary_version":"5.4.0-1143.152"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"id":"CVE-2021-47599","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48875","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-49072","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2022-49267","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-49927","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-56640","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}]},{"id":"CVE-2025-21780","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-40215"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8098-5.json"}}],"schema_version":"1.8.0"}