Ubuntu issues ten kernel notices citing Arm TLB flaw
Ubuntu issued ten Linux kernel notices from 21 to 25 September 2026; six cite Arm TLB flaw CVE-2025-10263, and Azure USN-8728-2 also cites AMD Zen 2 CVE-2025-54518.
Between 21 and 25 September 2026, Ubuntu published ten Linux kernel security notices for generic, Azure, IBM, NVIDIA, and Oracle builds. The flaw named most often is CVE-2025-10263, in USN-8726-3, USN-8726-4, USN-8728-2, USN-8817-1, USN-8818-1, and USN-8818-2: on some Arm processors a broadcast TLB invalidation can complete before memory writes made through the invalidated translation are globally observed, letting a local attacker write memory after permission was revoked and possibly bypass protections or escalate privileges. Azure notice USN-8728-2 also names CVE-2025-54518, incomplete isolation of shared resources in the operation cache on some AMD Zen 2 processors that may allow local privilege escalation, and refers to further unnamed issues. Four notices—USN-8761-3, USN-8729-3, USN-8760-2, and USN-8802-1—list no CVE identifiers; three say an attacker could possibly compromise a system, while USN-8761-3 only describes the subsystems fixed. Patches touch ARM32, ARM64, PowerPC, RISC-V, S390, and x86; compute acceleration, Bluetooth, GPU, InfiniBand, network including Microsoft Azure MANA, SCSI, and SPI; cryptographic APIs, ACPI, EFI, Netfilter, UAPI, and the kernel build system; NTFS3, SMB, exFAT, and the NFS client; and TCM, B.A.T.M.A.N., and HSR. The notices do not contradict one another: USN-8726-3 describes the Arm issue more briefly as a TLB-invalidation memory-protection bypass, and none reports exploitation in the wild.
- Ten Ubuntu Linux kernel notices, 21–25 September 2026: generic USN-8729-3 (21 Sep), USN-8726-4 (22 Sep), USN-8817-1 and USN-8818-1 (24 Sep); Azure USN-8761-3 (21 Sep) and USN-8728-2 (22 Sep); IBM USN-8726-3 (21 Sep) and USN-8818-2 (25…
- CVE-2025-10263 is named in six notices (USN-8726-3, USN-8726-4, USN-8728-2, USN-8817-1, USN-8818-1, USN-8818-2): on some Arm processors a broadcast TLB invalidation can finish before related memory writes are globally observed, so a local…
- Azure USN-8728-2 also names CVE-2025-54518, incomplete isolation of shared resources in the operation cache on some AMD Zen 2 processors that may allow local privilege escalation, plus further unnamed kernel issues.
- USN-8761-3, USN-8729-3, USN-8760-2, and USN-8802-1 list no CVE identifiers; the last three say an attacker could possibly compromise a system, while USN-8761-3 only describes corrected flaws.
- Fixes span ARM32, ARM64, PowerPC, RISC-V, S390, and x86; compute acceleration, Bluetooth, GPU, InfiniBand, network (including Microsoft Azure MANA), SCSI, and SPI; crypto APIs, ACPI, EFI, Netfilter, UAPI, and the kernel build system;…
Coverage timelineoldest first · each row is one article
- · 5d agoUSN-8761-3: Linux kernel (Azure) vulnerabilities
Ubuntu Security Notices· 45
Ubuntu patches Linux kernel vulnerabilities affecting Azure VMs across ARM, GPU, network, and file system subsystems.
- · 5d agoUSN-8729-3: Linux kernel vulnerabilities
Ubuntu Security Notices· 60
Ubuntu patches multiple Linux kernel vulnerabilities affecting ARM, GPU, network drivers, and file systems.
- · 5d agoUSN-8726-3: Linux kernel (IBM) vulnerabilities
Ubuntu Security Notices· 25
Ubuntu kernel update patches a privilege escalation flaw (CVE-2025-10263) in Arm processors affecting IBM systems.
Vulnerabilities in this storyAll →
- CVE-2025-102639.1<1%Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &…published
- CVE-2025-545187.3<1%Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a…