USN-7935-1

Source
https://ubuntu.com/security/notices/USN-7935-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7935-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7935-1
Upstream
Related
Published
2025-12-15T23:35:24.357239Z
Modified
2025-12-23T06:46:43.497470Z
Summary
linux-azure, linux-azure-6.8 vulnerabilities
Details

Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300)

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - HSI subsystem; - Media drivers; - Network drivers; - Bluetooth subsystem; - Timer subsystem; - Memory management; - Appletalk network protocol; - Netfilter; - TLS protocol; (CVE-2025-21729, CVE-2025-37838, CVE-2025-37958, CVE-2025-38118, CVE-2025-38227, CVE-2025-38352, CVE-2025-38616, CVE-2025-38666, CVE-2025-38678, CVE-2025-39964, CVE-2025-39993, CVE-2025-40018)

References

Affected packages

Ubuntu:22.04:LTS / linux-azure-6.8

Package

Name
linux-azure-6.8
Purl
pkg:deb/ubuntu/linux-azure-6.8@6.8.0-1044.50~22.04.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.8.0-1044.50~22.04.1

Affected versions

6.*

6.8.0-1008.8~22.04.1
6.8.0-1009.9~22.04.1
6.8.0-1010.10~22.04.1
6.8.0-1012.14~22.04.1
6.8.0-1013.15~22.04.1
6.8.0-1014.16~22.04.1
6.8.0-1015.17~22.04.2
6.8.0-1017.20~22.04.1
6.8.0-1018.21~22.04.1
6.8.0-1020.23~22.04.1
6.8.0-1021.25~22.04.1
6.8.0-1025.30~22.04.1
6.8.0-1026.31~22.04.1
6.8.0-1027.32~22.04.1
6.8.0-1028.33~22.04.1
6.8.0-1029.34~22.04.1
6.8.0-1030.35~22.04.1
6.8.0-1031.36~22.04.1
6.8.0-1034.39~22.04.1
6.8.0-1036.42~22.04.1
6.8.0-1040.46~22.04.1
6.8.0-1041.47~22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-azure-6.8-cloud-tools-6.8.0-1044"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-azure-6.8-headers-6.8.0-1044"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-azure-6.8-tools-6.8.0-1044"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-buildinfo-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-cloud-tools-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-headers-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-image-unsigned-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-modules-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-modules-extra-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-modules-involflt-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-modules-iwlwifi-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50~22.04.1",
            "binary_name": "linux-tools-6.8.0-1044-azure"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7935-1.json"

cves_map

{
    "cves": [
        {
            "id": "CVE-2025-21729",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-37838",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-37958",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-38118",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        },
        {
            "id": "CVE-2025-38227",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-38352",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        },
        {
            "id": "CVE-2025-38616",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-38666",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        },
        {
            "id": "CVE-2025-38678",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-39964",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-39993",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-40018",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-40300",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}

Ubuntu:24.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@6.8.0-1044.50?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.8.0-1044.50

Affected versions

6.*

6.5.0-1007.7
6.6.0-1001.1
6.8.0-1001.1
6.8.0-1005.5
6.8.0-1006.6
6.8.0-1007.7
6.8.0-1008.8
6.8.0-1009.9
6.8.0-1010.10
6.8.0-1012.14
6.8.0-1013.15
6.8.0-1014.16
6.8.0-1015.17
6.8.0-1016.18
6.8.0-1017.20
6.8.0-1018.21
6.8.0-1020.23
6.8.0-1021.25
6.8.0-1025.30
6.8.0-1026.31
6.8.0-1027.32
6.8.0-1028.33
6.8.0-1029.34
6.8.0-1030.35
6.8.0-1031.36
6.8.0-1034.39
6.8.0-1038.44
6.8.0-1040.46
6.8.0-1041.47
6.8.0-1042.48

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-azure-cloud-tools-6.8.0-1044"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-azure-headers-6.8.0-1044"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-azure-tools-6.8.0-1044"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-buildinfo-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-cloud-tools-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-headers-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-image-unsigned-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-modules-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-modules-extra-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-modules-involflt-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-modules-iwlwifi-6.8.0-1044-azure"
        },
        {
            "binary_version": "6.8.0-1044.50",
            "binary_name": "linux-tools-6.8.0-1044-azure"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7935-1.json"

cves_map

{
    "cves": [
        {
            "id": "CVE-2025-21729",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-37838",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-37958",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-38118",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        },
        {
            "id": "CVE-2025-38227",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-38352",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        },
        {
            "id": "CVE-2025-38616",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-38666",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        },
        {
            "id": "CVE-2025-38678",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-39964",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-39993",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-40018",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-40300",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}