USN-8871-1: Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu patched Raspberry Pi Linux kernel flaws, including an Arm TLB bug that may allow local privilege escalation.
Ubuntu published USN-8871-1 for its Raspberry Pi Linux kernel packages. CVE-2025-10263 involves Arm processors completing a broadcast TLB invalidation before related memory writes are globally visible, which a local attacker could use to write memory after permissions were revoked and possibly escalate privileges. The update also addresses flaws in the ARM64 architecture, InfiniBand and network drivers, the TCM subsystem, exFAT, and the NFS client. The notice does not report active exploitation.
- CVE-2025-10263 is an Arm TLB invalidation bug that may allow local privilege escalation
- Fixes also cover ARM64, InfiniBand, network drivers, TCM, exFAT, and the NFS client
- The notice applies to Ubuntu's Raspberry Pi Linux kernel packages
- No active exploitation is reported
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; -…
This source does not provide full text. Read it at ubuntu.com.