USN-8817-1: Linux kernel vulnerabilities
Ubuntu USN-8817-1 fixes Linux kernel bugs, including an Arm TLB flaw that may enable local privilege escalation.
Ubuntu USN-8817-1 corrects several Linux kernel vulnerabilities, including CVE-2025-10263. On some Arm processors, a broadcast TLB invalidation can finish before writes made through the invalidated translation are globally visible, allowing a local attacker to change memory after permission was revoked and possibly escalate privileges. Additional fixes cover ARM64, InfiniBand drivers, network drivers, the TCM subsystem, B.A.T.M.A.N. meshing, and the HSR protocol. No active exploitation is stated.
- CVE-2025-10263 lets a local attacker bypass Arm memory protections via a TLB race.
- Patches also touch ARM64, InfiniBand, network drivers, TCM, B.A.T.M.A.N., and HSR.
- Impact described includes privilege escalation or system compromise.
- No in-the-wild exploitation is reported in USN-8817-1.
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; -…
This source does not provide full text. Read it at ubuntu.com.