Skip to content
USN-8726-1: Linux kernel vulnerabilities

USN-8726-1: Linux kernel vulnerabilities

Ubuntu September 7, 2026

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. ( CVE-2025-10263 )

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:

User-space API (UAPI);

Block layer subsystem;

Compute Acceleration Framework;

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. ( CVE-2025-10263 )

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:

User-space API (UAPI);

Block layer subsystem;

Compute Acceleration Framework;

Compressed RAM block device driver;

Character device driver;

Hardware random number generator core;

CPU frequency scaling framework;

Hardware crypto device drivers;

Buffer Sharing and Synchronization framework;

Intel Stratix 10 firmware drivers;

CoreSight HW tracing drivers;

Input Device core drivers;

Input Device (Mouse) drivers;

Multiple devices driver;

Multifunction device drivers;

Ethernet bonding driver;

Mellanox network drivers;

MediaTek network drivers;

NVMEM (Non Volatile Memory) drivers;

Pin controllers subsystem;

x86 platform drivers;

System reset/shutdown drivers;

Power sequencing drivers;

Voltage and Current Regulator drivers;

Media staging drivers;

Realtek RTL8723BS SDIO drivers;

VME bus staging drivers;

Trusted Execution Environment drivers;

Thunderbolt and USB4 drivers;

DesignWare USB3 driver;

Faraday FOTG210 USB2 dual-role controller driver;

USB Host Controller drivers;

Siemens ID Mouse USB driver;

IOWarrior USB driver;

LD Didactic USB driver;

LEGO USB Tower driver;

Intel USBIO USB I/O expander driver;

USS720 USB parallel port adapter driver;

MediaTek USB3 DRD driver;

USB Type-C Port Controller Manager driver;

USB Type-C Connector System Software Interface driver;

File systems infrastructure;

FUSE (File system in Userspace);

Network file system (NFS) client;

Network file system (NFS) server daemon;

SMB network file system;

Software nodes and device properties;

Glob pattern matching library;

Restartable sequences system call mechanism;

Socket messages infrastructure;

Network traffic control;

TCP network protocol;

Kernel fork() syscall;

Kernel module support;

Scheduler infrastructure;

Signal handling mechanism;

Tracing infrastructure;

Debug objects infrastructure;

6LoWPAN network protocol;

IEEE 802 network protocols;

9P file system network protocol;

B.A.T.M.A.N. meshing protocol;

HSR network protocol;

IEEE802154.4 network protocol;

IEEE 802.15.4 subsystem;

Qualcomm IPC Router (QRTR);

VMware vSockets driver;

AppArmor security module;

Linux Security Modules (LSM) Framework;

Apple Onboard Audio ALSA driver;

FireWire sound drivers;

Gravis UltraSound ALSA driver;

C-Media CMI8x38 ALSA driver;

ESS Solo-1 ALSA driver;

ICE1712/ICE1724 (Envy24) ALSA driver;

Yamaha YMFPCI ALSA driver;

Wolfson Microelectronics audio codecs;

SoundWire (SDCA) ASoC drivers;

After a standard system update you need to reboot your computer to make all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.

The problem can be corrected by updating your system to the following package versions:

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Have additional questions?

Talk to a member of the team ›

Extracted Entities