USN-8818-2: Linux kernel (IBM) vulnerabilities
Ubuntu's IBM kernel update fixes CVE-2025-10263, a local Arm TLB memory-permission bypass.
Ubuntu USN-8818-2 patches Linux kernel vulnerabilities in the IBM kernel build. CVE-2025-10263 affects some Arm processors that can complete a broadcast TLB invalidation before related memory writes are globally observed, allowing a local attacker to write memory after permissions were revoked and possibly escalate privileges. The update also addresses issues in ARM64, InfiniBand, network drivers, TCM, exFAT, and the NFS client. Exploitation in the wild is not reported.
- CVE-2025-10263 is a local Arm TLB invalidation race.
- A local attacker may write memory after access was revoked.
- The flaw could bypass memory protections or escalate privileges.
- USN-8818-2 also patches other IBM kernel subsystems.
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; -…
This source does not provide full text. Read it at ubuntu.com.