USN-8726-4: Linux kernel vulnerabilities
Ubuntu's USN-8726-4 fixes Linux kernel flaws, including an Arm TLB issue enabling possible local privilege escalation.
Ubuntu issued USN-8726-4 for Linux kernel vulnerabilities. The named issue, CVE-2025-10263, is an Arm processor condition where a broadcast TLB invalidation can complete before memory writes using the invalidated translation are globally observed, possibly letting a local attacker bypass protections or escalate privileges. The update also corrects flaws across ARM64, ARM32, RISC-V, and S390 architectures, the user-space API, and the kernel build system. The notice does not report active exploitation.
- USN-8726-4 covers generic Linux kernel packages.
- CVE-2025-10263 is an Arm broadcast TLB invalidation issue that may bypass memory protections.
- Fixes also touch ARM64, ARM32, RISC-V, S390, UAPI, and the kernel build system.
- Local impact is described; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; -…
This source does not provide full text. Read it at ubuntu.com.