Ubuntu kernel notices fix Arm TLB flaw and other bugs
From 24–29 September 2026 Ubuntu patched Linux kernel flaws including an Arm TLB privilege-escalation bug, while Canada urged updates to multiple kernel branches.
Between 24 and 29 September 2026 Ubuntu published nine Linux kernel security notices. USN-8816-1 patches flaws across ARM64, S390, and x86 plus drivers and filesystems including DRBD, InfiniBand, NVMe, MANA, Virtio Host, Xen, NFS, NTFS3, and OCFS2, but names no CVEs. CVE-2025-10263, an Arm broadcast TLB invalidation race that can let a local attacker write memory after permission was revoked and possibly escalate privileges, is fixed in USN-8817-1 and in USN-8818-1, USN-8818-2 (IBM), and USN-8818-3; USN-8817-1 also lists B.A.T.M.A.N. and HSR, while the 8818 series lists exFAT and the NFS client. USN-8819-1, USN-8819-2, and USN-8819-3 fix NFS server, IPv6, and Netfilter flaws CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221, and USN-8729-5 updates the AWS FIPS kernel without listing CVE IDs. Canada's AV26-970 (28 September 2026) separately says stable kernels before 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.110, 6.18.52, and 7.2.6, plus kernels before 4.7, need updates, but names no CVE, so these reports do not tie it to a specific Ubuntu notice. None of the sources report exploitation in the wild; stated impact ranges from local privilege escalation for CVE-2025-10263 to possible system compromise.
- Between 2026-09-24 and 2026-09-29 Ubuntu published nine Linux kernel notices: USN-8816-1, USN-8817-1, USN-8818-1, USN-8818-2 (IBM), USN-8818-3, USN-8819-1, USN-8819-2, USN-8819-3, and USN-8729-5 (AWS FIPS).
- CVE-2025-10263 is an Arm broadcast TLB invalidation race: on some Arm processors invalidation can finish before related writes are globally visible, letting a local attacker write memory after permission was revoked, bypass protections,…
- CVE-2025-10263 is addressed in USN-8817-1 and USN-8818-1/-2/-3; USN-8817-1 also covers ARM64, InfiniBand, network drivers, TCM, B.A.T.M.A.N., and HSR, while the 8818 series also covers ARM64, InfiniBand, network drivers, TCM, exFAT, and…
- USN-8819-1, USN-8819-2, and USN-8819-3 fix NFS server, IPv6, and Netfilter flaws tracked as CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221; Ubuntu says an attacker could possibly compromise a system.
- USN-8816-1 (ARM64, S390, x86, DRBD, InfiniBand, NVMe, MANA, Virtio Host, Xen, NFS, NTFS3, OCFS2) and USN-8729-5 (ARM, PowerPC, Bluetooth, GPU, InfiniBand, network drivers, Microsoft Azure Network Adapter, SCSI, NTFS3, SMB) list no CVE…
- On 2026-09-28 the Canadian Centre for Cyber Security issued AV26-970, saying kernels before 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.110, 6.18.52, and 7.2.6, plus kernels before 4.7, need updates; it names no CVE and describes no impact.
Coverage timelineoldest first · each row is one article
- · 5d agoUSN-8816-1: Linux kernel vulnerabilities
Ubuntu Security Notices· 32
Ubuntu patched multiple Linux kernel flaws across architectures, drivers, and filesystems that could allow system compromise.
- · 5d agoUSN-8817-1: Linux kernel vulnerabilities
Ubuntu Security Notices· 52
Ubuntu USN-8817-1 fixes Linux kernel bugs, including an Arm TLB flaw that may enable local privilege escalation.
- · 5d agoUSN-8818-1: Linux kernel vulnerabilities
Ubuntu Security Notices· 52
Ubuntu kernel update fixes an Arm TLB race that may allow local privilege escalation, plus other driver and filesystem flaws.
Vulnerabilities in this storyAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
- CVE-2025-387247.8<1%Linux kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that…