USN-8801-1: Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN-8801-1 patches Linux kernel flaws for Azure CVM images, including an Arm TLB invalidation privilege escalation bug.
Ubuntu issued USN-8801-1 correcting several Linux kernel vulnerabilities affecting Azure Confidential VM images. CVE-2025-10263 stems from some Arm processors completing broadcast TLB invalidation before memory writes through the invalidated translation were globally observed, letting a local attacker bypass memory protections or escalate privileges. Additional fixes address flaws in the character device driver, networking core, IPv6, and Unix domain socket subsystems (CVE-2026-52938, CVE-2026-53325, CVE-2026-53361).
- USN-8801-1 targets Linux kernel for Azure Confidential VM images
- CVE-2025-10263 allows local privilege escalation on affected Arm processors
- Fixes cover character device, networking core, IPv6, and Unix domain sockets
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
- CVE-2026-529385.5<1%Linux kernel: bpf
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Character device driver; - Networking core; - IPv6 networking; - Unix domain sockets; (CVE-2026-52938, CVE-2026-53325, CVE-2026-53361,…
This source does not provide full text. Read it at ubuntu.com.