ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 6 sources: “Linux kernel local privilege escalation wave: Copy Fail, ZcopyReaper and IPv6 use-after-free drive CERT-EU, Ubuntu and ZDI advisories” — merged summary and timeline →

USN-8727-1: Linux kernel (OEM) vulnerabilities

mediumAdvisoryimportance 22CVE-2025-10263
AI summary · glm-5.3-flash

Ubuntu issued kernel security update USN-8727-1 for OEM kernels, fixing an Arm TLB invalidation flaw (CVE-2025-10263) allowing local privilege escalation.

Ubuntu released USN-8727-1, a security update for the OEM variant of the Linux kernel. It fixes CVE-2025-10263, in which certain Arm processors complete broadcast TLB invalidation before related memory writes are globally observed, potentially letting local attackers bypass memory protections or escalate privileges. The notice also corrects additional kernel flaws across ARM64, ARM32, RISC-V, S390 and other subsystems.

  • Fixes Arm TLB invalidation flaw allowing memory-protection bypass (CVE-2025-10263)
  • Addresses additional kernel flaws in ARM64, ARM32, RISC-V, S390 subsystems
  • Applies to Ubuntu OEM kernel builds
VendorsUbuntu
ProductsLinux kernel
OrganizationsArm

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10263
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C,

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

NVD description · AI analysis pending
9.1<1%
Full article

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; -…

This source does not provide full text. Read it at ubuntu.com.