ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 19 sources: “Ubuntu roundup (2026-09-16 to 2026-09-18): ten USNs fix 16 CVEs, including Rclone unauthenticated command execution and Arm kernel TLB race” — merged summary and timeline →

USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities

mediumAdvisoryimportance 25CVE-2025-10263
AI summary · glm-5.3-flash

Ubuntu USN-8781-1 patches Linux kernel NVIDIA Tegra flaws including CVE-2025-10263, an Arm TLB race enabling local privilege escalation.

USN-8781-1 fixes Linux kernel vulnerabilities in Ubuntu builds for NVIDIA Tegra, including CVE-2025-10263, where some Arm processors complete broadcast TLB invalidation before related memory writes are globally observed. A local attacker could exploit this to write to memory after permissions were revoked, bypassing memory protections or escalating privileges. The update also corrects flaws across ARM64, ARM32, PowerPC, RISC-V, UAPI, and kernel build subsystems.

  • CVE-2025-10263: Arm TLB invalidation race enables local privilege escalation
  • Affects Ubuntu Linux kernel builds for NVIDIA Tegra devices
  • Update also fixes flaws in multiple kernel subsystems

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10263
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C,

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

NVD description · AI analysis pending
9.1<1%
Full article

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - PowerPC architecture; - RISC-V…

This source does not provide full text. Read it at ubuntu.com.