USN-8817-2: Linux kernel (AWS FIPS) vulnerabilities
Ubuntu patched AWS FIPS Linux kernel flaws, including an Arm TLB bug that may enable local privilege escalation.
Ubuntu issued USN-8817-2 for the AWS FIPS Linux kernel. The notice includes CVE-2025-10263, where some Arm processors can finish a broadcast TLB invalidation before memory writes through the old translation are globally visible, potentially enabling a local attacker to bypass protections or escalate privileges. Additional fixes cover ARM64, InfiniBand and network drivers, TCM, B.A.T.M.A.N., and HSR. Active exploitation is not stated.
- USN-8817-2 updates the Ubuntu AWS FIPS Linux kernel.
- CVE-2025-10263 may let a local attacker bypass memory protections or escalate privileges.
- Patches also cover ARM64, InfiniBand, network drivers, TCM, B.A.T.M.A.N., and HSR.
- The notice does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; -…
This source does not provide full text. Read it at ubuntu.com.