USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu patches CVE-2025-10263, an Arm TLB invalidation flaw letting local attackers bypass memory protections or escalate privileges, plus other kernel fixes for Raspberry Pi.
Ubuntu released USN-8726-2 for the Linux kernel on the Raspberry Pi variant. It fixes CVE-2025-10263, where some Arm processors complete a broadcast TLB invalidation before associated memory writes are globally observed, allowing a local attacker to write to memory after permissions were revoked, potentially bypassing memory protections or escalating privileges. The update also corrects flaws across ARM64, ARM32, RISC-V, and S390 architectures and other kernel subsystems.
- Fixes CVE-2025-10263: Arm TLB invalidation race enabling local privilege escalation or memory protection bypass.
- Applies to Ubuntu's Linux kernel Raspberry Pi variant (USN-8726-2).
- Also corrects flaws in ARM64, ARM32, RISC-V, S390 and other subsystems.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. NVD description · AI analysis pending | 9.1 | <1% | — | — |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; -…
This source does not provide full text. Read it at ubuntu.com.