Canonical has published USN-8864-1, an Ubuntu Security Notice correcting multiple vulnerabilities in the Linux kernel. According to the advisory, an attacker could use these flaws to compromise the system — language Canonical reserves for issues with meaningful privilege-escalation or remote-compromise potential. The affected subsystems are three of the most exposed components of any Linux host:
- Network File System (NFS) server daemon — kernel code reachable by any client permitted to mount or probe an NFS export, which on misconfigured networks often means any client on the segment
- IPv6 networking — attack surface reachable remotely, including by hosts that administrators have quietly forgotten are IPv6-reachable via SLAAC/autoconfiguration even where IPv4 is tightly filtered
- Netfilter — the packet-filtering framework underpinning iptables/nftables; flaws here are a classic route from an unprivileged local process to root, and are heavily favored in local privilege-escalation (LPE) exploit chains
The notice maps to three CVEs: CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221. If you operate Ubuntu servers — particularly anything running nfs-kernel-server, handling IPv6 traffic, or relying on netfilter for tenant isolation (container hosts, hypervisors, firewalls) — treat this as a patch-this-week item, not a patch-this-quarter item. Kernel LPEs are the connective tissue of nearly every successful Linux intrusion we respond to: initial access comes from somewhere else, but a kernel bug is what turns a low-privilege web shell into full root.
Technical Analysis
Affected Products and Platforms
USN-8864-1 applies to supported Ubuntu releases shipping the affected kernel packages. As with all Ubuntu kernel USNs, the fix is delivered via updated kernel packages for each supported release's HWE and GA kernel flavors (e.g., linux-image-generic, linux-image-aws, linux-image-azure, linux-image-gcp, and OEM variants). Defenders should:
- Check the official notice page for the exact fixed package versions per release
- Inventory every Ubuntu host, including cloud images, container base images, and appliances built on Ubuntu (many network appliances, backup appliances, and IoT/edge devices embed Ubuntu kernels and never see routine patching)
- Pay special attention to hosts that have not rebooted into a recently installed kernel — a surprisingly common condition we find during IR engagements, where
aptinstalled the fix months ago but the running kernel is still vulnerable
The Vulnerabilities
- CVE-2025-38724 — flaw in one of the three named subsystems (NFS server, IPv6, or Netfilter per the notice grouping)
- CVE-2026-53131 — as above
- CVE-2026-53221 — as above
Canonical's notice groups the CVEs by subsystem rather than one-to-one, so defenders should treat all three CVEs as affecting the union of the named subsystems until per-CVE mappings are confirmed on the notice page and in the Ubuntu CVE tracker. Check the notice for per-CVE CVSS scores as Canonical publishes them; Ubuntu kernel notices of this type commonly rate in the High band (7.x) where local privilege escalation or remote kernel memory corruption is possible.
Why These Subsystems Matter (Defender's Perspective)
NFS server daemon (nfsd): Kernel-space NFS code parses requests from network clients. Memory-corruption bugs in nfsd are remotely triggerable by any host that can reach TCP/UDP 2049 — and in environments with broad exports (*(rw) to a subnet, or legacy NFSv3 with loose mountd rules), that reachability is wider than most teams believe. A compromised internal host or a rogue VM becomes a launch point.
IPv6 networking: IPv6 kernel paths (neighbor discovery, extension headers, fragmentation handling) are remotely reachable without any application listening. We routinely find organizations that filter IPv4 aggressively but leave IPv6 wide open — or don't even know their hosts have globally routable IPv6 addresses. An IPv6 kernel flaw can be triggered by crafted packets from an adjacent network segment or, worse, from the internet.
Netfilter: Netfilter vulnerabilities are the workhorse of Linux LPE exploits. They are typically reachable from an unprivileged local process via setsockopt(), nft netlink messages, or packet paths. A netfilter bug means: any foothold on the host — a compromised service account, a container escape partial, a malicious package script — can potentially become root.
Exploitation Status
At the time of this writing, the USN does not indicate confirmed in-the-wild exploitation, and none of the three CVEs has been publicly listed in the CISA Known Exploited Vulnerabilities catalog. That said, two cautionary realities from the field:
- Ubuntu kernel CVEs receive public technical write-ups fast. Netfilter bugs in particular have a well-established pipeline from patch to public root exploit — often within weeks. The patch diff itself is the exploit roadmap.
- The window between "fixed" and "mass-exploited" keeps shrinking. Defenders should assume exploitability and prioritize accordingly, especially on multi-tenant and internet-adjacent hosts.
Verify current exploitation status against the CISA KEV catalog and the Ubuntu CVE tracker before finalizing your prioritization.
Detection & Response
Kernel-level exploitation is difficult to detect with signature-style rules — by design, a successful kernel exploit often leaves few userspace artifacts. The realistic detection strategy focuses on behavioral signals around exploitation attempts (crashes, oops, tainted kernels), post-exploitation activity (root shells, unexpected kernel module loads, tampering with netfilter rules), and exposure identification (unpatched kernels, reachable NFS/IPv6 services). The detections below are tuned for high-fidelity alerting in a production SOC.
Sigma Rules
---
title: Linux Kernel Oops or Bug Indicating Possible Kernel Exploitation Attempt
id: 3f8a2c71-9b4d-4e62-a7c3-5d1e8f0a2b94
status: experimental
description: Detects kernel oops, BUG, or general protection fault messages in kernel logs. Failed exploitation attempts against kernel vulnerabilities (e.g., NFS, IPv6, Netfilter flaws addressed in USN-8864-1) frequently crash the kernel or trigger oops messages before a working exploit is achieved. A cluster of oops events on a single host warrants immediate investigation.
references:
- https://ubuntu.com/security/notices/USN-8864-1
- https://attack.mitre.org/techniques/T1068/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.privilege_escalation
- attack.t1068
logsource:
product: linux
service: kern
detection:
selection:
- 'kernel BUG at'
- 'general protection fault'
- 'BUG: unable to handle kernel'
- 'Oops:'
- 'kernel NULL pointer dereference'
- 'WARNING: CPU:'
condition: selection
falsepositives:
- Buggy third-party or out-of-tree kernel modules (common with vendor drivers)
- Hardware faults causing intermittent oops events
level: high
---
title: Unexpected Kernel Module Load on Server
id: 8c2e5b14-7d3a-4f91-b6e8-2a9c4d7e1f35
status: experimental
description: Detects loading of kernel modules via insmod/modprobe by non-standard processes or from non-standard paths. Successful kernel exploitation (including Netfilter LPE chains like those patched in USN-8864-1) is often followed by loading a rootkit module or helper module to establish persistence or hide artifacts.
references:
- https://ubuntu.com/security/notices/USN-8864-1
- https://attack.mitre.org/techniques/T1547/006/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1547.006
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith:
- '/insmod'
- '/modprobe'
filter_kmod_builtin:
CommandLine|contains:
- '/lib/modules/'
filter_package_managers:
ParentImage|endswith:
- '/dpkg'
- '/apt'
- '/apt-get'
- '/unattended-upgrade'
- '/dkms'
condition: selection and not 1 of filter_*
falsepositives:
- Legitimate DKMS rebuilds after kernel updates (filter via parent process)
- Hardware enablement scripts on first boot
level: high
---
title: Root Shell Spawned by Network-Facing Service or Non-Login Process
id: b41d9e07-2c6f-48a3-9d52-7e0a3f6b8c19
status: experimental
description: Detects interactive shells spawned as root by parent processes that should never spawn shells, such as the NFS kernel thread wrappers' userspace helpers, web servers, or container runtimes. This is a hallmark of successful privilege escalation following kernel exploitation (e.g., via the Netfilter or NFS flaws in USN-8864-1).
references:
- https://ubuntu.com/security/notices/USN-8864-1
- https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.execution
- attack.privilege_escalation
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith:
- '/bash'
- '/sh'
- '/dash'
- '/zsh'
User: root
ParentImage|endswith:
- '/nfsd'
- '/rpc.mountd'
- '/apache2'
- '/nginx'
- '/containerd'
- '/dockerd'
- '/java'
- '/php-fpm'
- '/node'
condition: selection
falsepositives:
- Rare administrative automation with unusual parentage (tune per environment)
level: critical
KQL (Microsoft Sentinel / Defender)
This query assumes Linux syslog/kernel logs are ingested into Sentinel via the Syslog or AMA connector. It hunts for the kernel exploitation signals above plus exposure indicators (NFS daemon running, IPv6 reachable) so you can triage your unpatched fleet from one pane of glass.
// Hunt: kernel exploitation signals + USN-8864-1 exposure on Linux hosts
// Part 1: Kernel oops/BUG/GPF events and unexpected module loads (possible exploit attempts)
let KernelSignals = Syslog
| where TimeGenerated > ago(7d)
| where Facility =~ "kern" or ProcessName =~ "kernel"
| where SyslogMessage has_any (
"kernel BUG at",
"general protection fault",
"BUG: unable to handle kernel",
"Oops:",
"kernel NULL pointer dereference",
"WARNING: CPU:",
"nf_tables", // netfilter subsystem errors
"nfsd" // NFS server daemon errors
)
| summarize EventCount = count(), SampleMessages = make_set(SyslogMessage, 3)
by Computer, bin(TimeGenerated, 1h)
| where EventCount >= 2 // suppress one-off hardware noise
| extend AlertType = "KernelExploitSignal";
// Part 2: Unexpected kernel module loads (post-exploitation / rootkit staging)
let ModuleLoads = Syslog
| where TimeGenerated > ago(7d)
| where ProcessName in~ ("insmod", "modprobe")
| where SyslogMessage !has "/lib/modules/"
| summarize by Computer, ProcessName, SyslogMessage, TimeGenerated
| extend AlertType = "UnexpectedModuleLoad";
union KernelSignals, ModuleLoads
| sort by TimeGenerated desc
// Tuning note: alert on hosts NOT yet running a fixed kernel (join against your
// CMDB/vuln scan data or the exposure check below). A kernel signal on an
// unpatched host is the highest-priority combination.
;
// Part 3 (run separately for exposure scoping): identify hosts with nfsd active
// or IPv6 globally reachable — the most exposed to USN-8864-1 pre-patch
Syslog
| where TimeGenerated > ago(24h)
| where SyslogMessage has "nfsd: starting" or ProcessName =~ "rpc.mountd"
| summarize by Computer
| join kind=inner (
// optional: join your vulnerability scan export for CVE-2025-38724 /
// CVE-2026-53131 / CVE-2026-53221 findings
externaldata(Host:string, KernelVersion:string)[
@"<vuln-scan-export-url>"
] with (format="csv") on $left.Computer == $right.Host
)
| project Computer, KernelVersion
Velociraptor VQL
This artifact enumerates running kernel version (to flag unpatched hosts), loaded out-of-tree/tainted kernel modules, and listeners on NFS/IPv6 — a fast scoping hunt across your Linux fleet.
-- USN-8864-1 scoping hunt: running kernel version, tainted modules, NFS/IPv6 exposure
SELECT {
SELECT * FROM execve(argv=['uname', '-r'])
} AS RunningKernel,
{
SELECT Pid, Name, Status, Address, Mask
FROM netstat()
WHERE (Name =~ 'nfsd|mountd|rpcbind' OR Address =~ '2049')
AND Status = 'LISTEN'
} AS NFSListeners,
{
SELECT * FROM glob(globs=['/proc/sys/kernel/tainted'])
} AS TaintFlag
FROM scope()
-- Companion artifact: enumerate loaded modules NOT from the distro kernel tree
-- (out-of-tree modules are both a taint source and a rootkit hiding spot)
SELECT Name, FullPath, Mtime
FROM glob(globs=['/sys/module/*/holders', '/sys/module/*'])
WHERE NOT FullPath =~ '/sys/module/(nf_|xt_|ip_|ipv6|nfsd|lockd|sunrpc|overlay|br_netfilter)'
ORDER BY Name
Remediation & Verification Script
#!/usr/bin/env bash
# USN-8864-1 remediation + verification (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
# Run as root. Safe to re-run; exits non-zero if the host remains exposed.
set -euo pipefail
# 1. Record the currently RUNNING kernel (not just the newest installed one)
echo "[i] Running kernel: $(uname -r)"
# 2. Pull the latest package metadata and check the Ubuntu CVE status tool
apt-get update -qq
/usr/bin/ubuntu-security-status --unavailable 2>/dev/null || true
# 3. Apply the kernel security update (and other pending security updates)
DEBIAN_FRONTEND=noninteractive apt-get install -y --only-upgrade \
linux-image-generic linux-headers-generic 2>/dev/null || \
DEBIAN_FRONTEND=noninteractive unattended-upgrade -d
# 4. Confirm a reboot is actually required and flag it loudly
if [ -f /var/run/reboot-required ]; then
echo "[!] REBOOT REQUIRED. Installed kernel: $(dpkg -l 'linux-image-*' | awk '/^ii/{print $2}' | sort -V | tail -1)"
echo "[!] The running kernel remains VULNERABLE until reboot. Schedule now."
fi
# 5. Post-reboot verification (run this section again after rebooting):
# Compare against the fixed versions listed at https://ubuntu.com/security/notices/USN-8864-1
FIXED_VERSION="<insert fixed kernel version from USN-8864-1>"
if dpkg --compare-versions "$(uname -r)" ge "$FIXED_VERSION"; then
echo "[+] Running kernel $(uname -r) meets or exceeds fixed version. OK."
else
echo "[-] STILL VULNERABLE: running $(uname -r), need >= $FIXED_VERSION" >&2
exit 1
fi
# 6. Reduce pre-patch exposure on hosts awaiting a maintenance window:
# - Restrict NFS exports to known clients (edit /etc/exports, then: exportfs -ra)
# - If NFS serving is not required on this host:
systemctl is-active --quiet nfs-server && echo "[!] nfs-server active — disable if not needed: systemctl disable --now nfs-server"
# - If IPv6 is not required (verify with your network team first!):
# sysctl -w net.ipv6.conf.all.disable_ipv6=1 # temporary until reboot
Remediation
- Patch immediately via standard Ubuntu channels. Apply USN-8864-1 with
apt-get update && apt-get upgrade(orunattended-upgradefor security-only), then reboot into the fixed kernel. The exact fixed package versions per Ubuntu release are listed on the official notice — verifyuname -ragainst that list after reboot. An installed-but-not-running patch provides zero protection. - Hunt for the "installed but not rebooted" gap fleet-wide. Check
/var/run/reboot-required, or compareuname -ragainst the newest installedlinux-image-*package, across every Ubuntu host. This is the single most common failure mode we see in kernel patch programs. - Prioritize by exposure: (a) internet-facing Ubuntu hosts, (b) hosts running
nfs-kernel-server, (c) multi-tenant systems — container hosts, hypervisors, shared CI runners — where a netfilter LPE breaks tenant isolation, (d) hosts with globally reachable IPv6, then (e) everything else. - Pre-patch workarounds for hosts awaiting a window:
- NFS: If the host doesn't need to serve NFS,
systemctl disable --now nfs-server rpcbind. If it does, lock/etc/exportsdown to specific client IPs (no wildcards/subnet-wide exports), runexportfs -ra, and firewall 2049 to those clients only. - IPv6: If IPv6 is not operationally required, disable it via sysctl (
net.ipv6.conf.all.disable_ipv6=1) as a temporary risk reducer — coordinate with network engineering first, and note this does not substitute for patching. - Netfilter: There is no practical runtime workaround for kernel netfilter flaws; restricting which users/processes can execute code on the host is the only mitigation. Minimize local accounts and container workloads on unpatched hosts.
- NFS: If the host doesn't need to serve NFS,
- Update golden images and IaC. Rebuild AMIs, cloud images, container base layers, and any embedded Ubuntu appliances so newly provisioned hosts aren't born vulnerable.
- Monitor for exploitation signals using the detections above during the patch window, and check the CISA KEV catalog — if any of these CVEs lands there, federal deadlines (typically ~2-3 weeks under BOD 22-01) apply, and private-sector organizations should treat that as their effective SLA too.
- Verify, don't assume. Close the loop with an authenticated vulnerability scan or configuration-compliance check confirming the running kernel version matches the fixed version on 100% of in-scope assets.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.