USN-8818-6: Linux kernel (FIPS) vulnerabilities
Ubuntu’s FIPS Linux kernel update fixes an Arm TLB flaw and other kernel bugs, including CVE-2025-10263.
Ubuntu Security Notice USN-8818-6 patches vulnerabilities in the FIPS Linux kernel. CVE-2025-10263 concerns some Arm processors completing a broadcast TLB invalidation before related memory writes are globally observed, which a local attacker might use to write memory after permission was revoked and to bypass protections or escalate privileges. The update also fixes flaws in ARM64, InfiniBand drivers, network drivers, the TCM subsystem, exFAT, and the NFS client. Active exploitation is not mentioned.
- CVE-2025-10263 is a local Arm TLB invalidation race.
- A local attacker might bypass memory protections or escalate privileges.
- The FIPS kernel update also covers ARM64, InfiniBand, networking, TCM, exFAT, and NFS.
- Ubuntu does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &… Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. |
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; -…
This source does not provide full text. Read it at ubuntu.com.