USN-8906-1: Linux kernel (IBM) vulnerabilities
Ubuntu patched IBM Linux kernel flaws, including a local Arm TLB issue tracked as CVE-2025-10263.
Ubuntu published USN-8906-1 for the Linux kernel used on IBM systems. CVE-2025-10263 describes Arm processors completing a broadcast TLB invalidation before related memory writes are globally observed, which a local attacker might use to write memory after permissions were revoked and escalate privileges. The update also fixes issues in ARM, MIPS, PowerPC, x86, the Intel NPU driver, and other subsystems. The notice does not report exploitation in the wild.
- USN-8906-1 updates IBM Linux kernel packages
- CVE-2025-10263 is a local Arm TLB memory-protection bypass
- Additional flaws span multiple architectures and drivers
- No in-the-wild exploitation is stated
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - ARM32 architecture; - MIPS architecture; - PowerPC architecture; - x86 architecture; - Intel NPU Driver; - Compute…
This source does not provide full text. Read it at ubuntu.com.