USN-8878-1: Linux kernel (GCP) vulnerabilities
Ubuntu's USN-8878-1 patches GCP Linux kernels for an i.MX crash and an Arm TLB privilege flaw.
Ubuntu Security Notice USN-8878-1 covers Linux kernel vulnerabilities in GCP images. CVE-2022-3114 is a null pointer dereference in the i.MX clock driver that a local attacker could use to cause a system crash. CVE-2025-10263 is an Arm processor TLB invalidation issue that could let a local attacker write memory after access was revoked, bypassing protections or escalating privileges. Exploitation is described as possible, not observed.
- USN-8878-1 updates Ubuntu's GCP Linux kernel packages.
- CVE-2022-3114 allows a local denial of service via an i.MX driver null pointer.
- CVE-2025-10263 may let a local attacker write memory after permissions are revoked.
- No in-the-wild exploitation is stated.
Vulnerabilities mentionedAll →
- CVE-2022-31145.5<1%An issue was discovered in the Linux kernel through 5.16-rc6published · linux linux kernel
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…
It was discovered that the i.MX clock driver in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-3114) It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were…
This source does not provide full text. Read it at ubuntu.com.