USN-8728-3: Linux kernel (Oracle) vulnerabilities
Ubuntu USN-8728-3 updates the Oracle cloud Linux kernel, fixing Arm TLB and AMD Zen 2 privilege escalation flaws.
Ubuntu issued USN-8728-3 for the Linux kernel (Oracle) package addressing several vulnerabilities. CVE-2025-10263 stems from some Arm processors completing broadcast TLB invalidation before memory writes were globally observed, allowing a local attacker to bypass memory protections or escalate privileges. CVE-2025-54518 involves AMD Zen 2 processors failing to isolate shared operation cache resources, enabling corruption of higher-privilege instructions and privilege escalation.
- CVE-2025-10263: Arm TLB invalidation flaw allows local privilege escalation
- CVE-2025-54518: AMD Zen 2 op-cache isolation flaw allows privilege escalation
- Affects Ubuntu's Oracle cloud Linux kernel package
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
- CVE-2025-545187.3<1%Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a…
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in…
This source does not provide full text. Read it at ubuntu.com.