Ubuntu kernel updates cover Arm TLB, NFS, and SMC-D flaws
Ubuntu patched multiple Linux kernels for an Arm TLB flaw and NFS, IPv6, and Netfilter bugs; a separate SMC-D flaw has a local root proof of concept.
Ubuntu issued a cluster of Linux kernel security notices from 29 September through 2 October 2026 for generic, FIPS, AWS, AWS FIPS, NVIDIA Tegra, and GKE builds. USN-8818-3, USN-8818-4, USN-8818-6, USN-8817-2, USN-8817-3, and USN-8849-1 include CVE-2025-10263, an Arm TLB invalidation race that a local attacker might use to write memory after permissions were revoked and possibly escalate privileges; none report active exploitation. Those updates also fix ARM64 and driver or subsystem issues, but AWS notices add B.A.T.M.A.N. and HSR while others mention exFAT, and sources disagree on whether the related NFS fix is in the NFS client or, for Tegra, the NFS server. USN-8819-3 and USN-8864-1 both patch CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221 in the NFS server, IPv6, and Netfilter, with Ubuntu saying an attacker could possibly compromise a system. USN-8816-4 for GKE describes broad kernel issues that could allow compromise but names no CVEs. Separately, GBHackers reported XBOW’s disclosure of CVE-2026-72018, a local CAP_NET_ADMIN out-of-bounds write in the SMC-D dibs_loopback driver whose proof of concept gained root in 22 of 100 boots on Ubuntu 24.04 with Linux 7.1.0-rc6 and mitigations disabled; Red Hat warned of memory corruption, denial of service, or code execution, and kernels 6.12.97, 6.18.40, and 7.1.5 or later are listed as unaffected.
- From 29 September to 2 October 2026 Ubuntu issued kernel notices including USN-8818-3, USN-8818-4, USN-8818-6, USN-8817-2, USN-8817-3, USN-8849-1, USN-8819-3, USN-8864-1, and USN-8816-4.
- CVE-2025-10263 is an Arm broadcast TLB invalidation issue that a local attacker might use to write memory after access was revoked, bypass protections, or escalate privileges; the notices do not report active exploitation.
- Affected flavors differ: generic, FIPS, and Tegra notices also cite ARM64, InfiniBand, network drivers, TCM, and exFAT, while AWS and AWS FIPS notices cite B.A.T.M.A.N. and HSR.
- Sources disagree on NFS scope: the USN-8818 series describes NFS client fixes, whereas USN-8849-1 for NVIDIA Tegra describes an NFS server fix.
- USN-8819-3 and USN-8864-1 both address CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221 in the NFS server, IPv6, and Netfilter; Ubuntu says compromise is possible and reports no in-the-wild exploitation.
- USN-8816-4 for the GKE kernel says issues across ARM64, s390, x86, DRBD, InfiniBand, NVMe, NFS, NTFS3, and Xen could allow compromise, but names no CVE identifiers.
- Separately, XBOW disclosed high-severity CVE-2026-72018, a local CAP_NET_ADMIN out-of-bounds write in the SMC-D dibs_loopback driver; its lab proof of concept gained root in 22 of 100 boots on Ubuntu 24.04 with Linux 7.1.0-rc6 and…
- Red Hat warned CVE-2026-72018 could cause memory corruption, denial of service, or code execution; kernels 6.12.97, 6.18.40, and 7.1.5 or later are listed as unaffected.
Coverage timelineoldest first · each row is one article
- · 3d agoUSN-8729-6: Linux kernel (AWS) vulnerabilities
Ubuntu Security Notices· 12
Ubuntu USN-8729-6 patches multiple Linux kernel flaws for AWS deployments across architectures and drivers.
- · 3d agoUSN-8816-2: Linux kernel vulnerabilities
Ubuntu Security Notices· 12
Ubuntu USN-8816-2 fixes multiple Linux kernel vulnerabilities across architecture, driver, and file system subsystems.
- · 3d agoUSN-8728-3: Linux kernel (Oracle) vulnerabilities
Ubuntu Security Notices· 18
Ubuntu USN-8728-3 updates the Oracle cloud Linux kernel, fixing Arm TLB and AMD Zen 2 privilege escalation flaws.
Vulnerabilities in this storyAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
- CVE-2025-387247.8<1%Linux kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that…