[Ksplice][Ubuntu-24.04-Updates] New Ksplice updates for Ubuntu 24.04 Noble (USN-7703-1)

Oracle Ksplice gregory.herrero at oracle.com
Wed Sep 10 20:17:48 UTC 2025


Synopsis: USN-7703-1 can now be patched using Ksplice
CVEs: CVE-2025-21759 CVE-2025-21787 CVE-2025-21790 CVE-2025-21791 CVE-2025-21795 CVE-2025-21836 CVE-2025-21844

Systems running Ubuntu 24.04 Noble can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-7703-1.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running Ubuntu 24.04
Noble install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2025-21759: Use-after-free in ipv6 networking driver.

* CVE-2025-21787: Denial-of-service in Ethernet team driver.

* CVE-2025-21790: Null pointer dereference in Virtual eXtensible Local Area Network (VXLAN) driver.

* CVE-2025-21791: Privilege escalation in layer 3 master device support.

* CVE-2025-21795: Remote denial-of-service in NFS server driver.

* CVE-2025-21836: Use-after-free in IO-uring subsystem.

* CVE-2025-21844: Denial-of-service in Common Internet File System (CIFS).

A missing check when using the SMB3 client could lead to a NULL
pointer dereference. A local attacker could use this flaw to cause a
denial-of-service.


* Information leak in USB Modem (CDC ACM) driver.

* Note: Oracle has determined some CVEs are not applicable.

The kernel is not affected by the following CVEs
since the code under consideration is not compiled.

CVE-2025-21785


SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-Ubuntu-24.04-updates mailing list