USN-8817-3: Linux kernel (AWS) vulnerabilities
Ubuntu patched AWS Linux kernel flaws, including an Arm TLB bug that may allow local privilege escalation.
Ubuntu published USN-8817-3 for the AWS Linux kernel. CVE-2025-10263 describes Arm processors that can finish a broadcast TLB invalidation before related writes are globally visible, which a local attacker might use to write memory after access was revoked. The update also fixes flaws in ARM64, InfiniBand and network drivers, the TCM subsystem, and the B.A.T.M.A.N. and HSR protocols. The notice does not report active exploitation.
- CVE-2025-10263 is an Arm TLB race that may allow local privilege escalation.
- USN-8817-3 updates Ubuntu's AWS Linux kernel packages.
- Fixes also cover ARM64, InfiniBand, network drivers, TCM, B.A.T.M.A.N., and HSR.
- The notice does not report that the flaws are being exploited.
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; -…
This source does not provide full text. Read it at ubuntu.com.