---
title: Spectre mitigation updates available for testing in Ubuntu Proposed
description: Canonical holds Ubuntu to the highest standards of security and quality.
   This week we published candidate Ubuntu kernels providing mitigation for CVE-2017-5715
  and CVE-2017-5753 (ie, Spectre / Variants 1 & 2) to their respective -proposed pockets
  for Ubuntu 17.10 (Artful), 16.04 LTS (Xenial), and 14.04 LTS (Trusty).  We have
  also expande […]
url: https://canonical.com/blog/spectre-mitigation-updates-available-for-testing-in-ubuntu-proposed?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Dustin Kirkland](https://canonical.com/blog/author/kirkland "More about Dustin Kirkland")

17 January 2018

# Spectre mitigation updates available for testing in Ubuntu Proposed

[cloud](https://canonical.com/blog/tag/cloud)
[Security](https://canonical.com/blog/tag/security)
[Server](https://canonical.com/blog/tag/server)
[Ubuntu Desktop](https://canonical.com/blog/tag/ubuntu-desktop)

---

Share the article

Canonical holds Ubuntu to the highest standards of security and quality.  This week we published candidate Ubuntu kernels providing mitigation for CVE-2017-5715 and CVE-2017-5753 (ie, Spectre / Variants 1 & 2) to their respective -proposed pockets for Ubuntu 17.10 (Artful), 16.04 LTS (Xenial), and 14.04 LTS (Trusty).  We have also expanded mitigation to cover s390x and ppc64el.

* <https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-5715.html>
* <https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-5753.html>

You are invited to test and provide feedback for the following updated Linux kernels.  We have also rebased all derivative kernels such as the public cloud kernels (Amazon, Google, Microsoft, etc) and the Hardware Enablement (HWE) kernels.

* 17.10 (Artful): linux-4.13.0-30.33
  + <https://launchpad.net/ubuntu/+source/linux/4.13.0-30.33>
* 16.04 LTS (Xenial): linux-4.4.0-111.134
  + <https://launchpad.net/ubuntu/+source/linux/4.4.0-111.134>
* 14.04 LTS (Trusty): linux-3.13.0-140.189
  + <https://launchpad.net/ubuntu/+source/linux/3.13.0-140.189>
* 17.04 is end-of-life and won’t be patched for either Meltdown or Spectre
  + <https://lists.ubuntu.com/archives/ubuntu-announce/2018-January/000227.html>

Updates for Ubuntu 12.04 ESM are in progress, and will be available for Canonical’s Ubuntu Advantage customers.  UA customers should reach out to Canonical support for access to candidate kernels.

* <https://www.ubuntu.com/esm>
* <https://support.canonical.com/>

We intend to promote the candidate kernels to the -security/-updates pocket for General Availability (GA) on Monday, January 22, 2018.

There is a corresponding intel-microcode update for many Intel CPUs, as well as an eventual amd64-microcode update, that will also need to be applied in order to fully mitigate Spectre.  In the interest of full disclosure, we understand from Intel that there are currently known issues with the intel-microcode binary:

* <https://newsroom.intel.com/news/firmware-updates-and-initial-performance-data-for-data-center-systems/>

Canonical QA and Hardware Certification teams are engaged in extensive, automated and manual testing of these kernels and the Intel microcode kernel updates on Ubuntu certified hardware, and Ubuntu certified public clouds.  The primary focus is on regression testing and security effectiveness.   We are actively investigating Google’s “Retpoline” toolchain-based approach, which requires rebuilding Ubuntu binaries but reduce performance impact of the mitigation.

For your reference, the following links explain how to enable Ubuntu’s Proposed repositories, and how to file Linux kernel bugs:

* <https://wiki.ubuntu.com/Testing/EnableProposed>
* <https://wiki.ubuntu.com/Kernel/Bugs>

The most current information will continue to be available at:

* <https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown>

@Canonical

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Arduino® VENTUNO™ Q is available for pre-order with Ubuntu pre-installed](https://canonical.com/blog/arduino-ventuno-q-is-available-for-pre-order-with-ubuntu-pre-installed)

London, UK – August 25, 2026 – Following our initial collaboration announcement in March 2026, Canonical and Arduino (a subsidiary of Qualcomm Technologies, Inc.) are excited...

[Canonical](https://canonical.com/blog/author/canonical)

25 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
