Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8121-1: Linux kernel (AWS FIPS) vulnerability

Multiple vulnerabilities in the AppArmor Linux kernel Security Module allow an unprivileged local attacker to arbitrarily load, replace, or remove AppArmor profiles, leading to denial of service, kernel memory disclosure, local privilege escalation, or container escape. The flaw affects the `linux-aws-fips` kernel packages for Ubuntu 20.04 LTS, specifically version `5.4.0-1156.166+fips1` and related FIPS metapackages. A fix requires updating to the patched kernel versions listed in the notice and a system reboot, with the caveat that an ABI change necessitates recompiling any third-party kernel modules.
Read Full Article →

Ubuntu Security Notices USN-8121-1 USN-8121-1: Linux kernel (AWS FIPS) vulnerability Publication date 24 March 2026 Overview The system could be made to run programs as an administrator. Releases 20.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages linux-aws-fips - Linux kernel for Amazon Web Services (AWS) systems with FIPS Details Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of service, exposure of sensitive information (kernel memory), local privilege escalation, or possibly escape a container. (LP: #2143853) Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of service, exposure of sensitive information (kernel memory), local privilege escalation, or possibly escape a container. (LP: #2143853) Update instructions After a standard system update you need to reboot your computer to make all the necessary changes. Learn more about how to get the fixes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 20.04 LTS focal linux-image-5.4.0-1156-aws-fips – 5.4.0-1156.166+fips1 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-aws-fips – 5.4.0.1156.103 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. linux-image-aws-fips-5.4 – 5.4.0.1156.103 FIPS Updates FIPS-140 certified package with security fixes. Available with Ubuntu Pro. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References https://launchpad.net/bugs/2143853 Have additional questions? Talk to a member of the team ›

Share this article