It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. ( CVE-2025-10263 ) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: ARM64 architecture; User-space API (UAPI); Kernel build system; ARM32 architecture; RISC-V architecture; S390 architecture; x86 architecture; Block layer subsystem; Cryptographic API; Compute Acceleration Framework; Intel NPU Driver; ACPI...
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. ( CVE-2025-10263 )
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
User-space API (UAPI);
Block layer subsystem;
Compute Acceleration Framework;
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. ( CVE-2025-10263 ) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: ARM64 architecture; User-space API (UAPI); Kernel build system; ARM32 architecture; RISC-V architecture; S390 architecture; x86 architecture; Block layer subsystem; Cryptographic API; Compute Acceleration Framework; Intel NPU Driver; ACPI drivers; Android drivers; Drivers core; Compressed RAM block device driver; Bluetooth drivers; Character device driver; Hardware random number generator core; CPU frequency scaling framework; Hardware crypto device drivers; Buffer Sharing and Synchronization framework; Intel Stratix 10 firmware drivers; FPGA Framework; GPIO subsystem; GPU drivers; HID subsystem; CoreSight HW tracing drivers; I2C subsystem; IIO subsystem; IIO ADC drivers; InfiniBand drivers; Input Device core drivers; Input Device (Mouse) drivers; IOMMU subsystem; IRQ chip drivers; Multiple devices driver; Media drivers; Multifunction device drivers; Fastrpc Driver; MMC subsystem; Ethernet bonding driver; Network drivers; Mellanox network drivers; MediaTek network drivers; NTB driver; NVME drivers; NVMEM (Non Volatile Memory) drivers; PCI subsystem; Pin controllers subsystem; x86 platform drivers; System reset/shutdown drivers; Power sequencing drivers; PTP clock framework; Voltage and Current Regulator drivers; RPMSG subsystem; SLIMbus drivers; SPI subsystem; Media staging drivers; Realtek RTL8723BS SDIO drivers; VME bus staging drivers; Trusted Execution Environment drivers; TTY drivers; Cadence USB3 driver; ULPI bus; USB core drivers; DesignWare USB3 driver; Faraday FOTG210 USB2 dual-role controller driver; USB Gadget drivers; USB Host Controller drivers; USB ChaosKey driver; Siemens ID Mouse USB driver; IOWarrior USB driver; LD Didactic USB driver; LEGO USB Tower driver; Intel USBIO USB I/O expander driver; USS720 USB parallel port adapter driver; MediaTek USB3 DRD driver; USB Serial drivers; USB Type-C Port Controller Manager driver; USB Type-C Connector System Software Interface driver; USB over IP driver; VFIO drivers; Framebuffer layer; Virtio drivers; BTRFS file system; EROFS file system; exFAT file system; F2FS file system; File systems infrastructure; FUSE (File system in Userspace); GFS2 file system; HFS file system; HFS+ file system; Network file system (NFS) client; Network file system (NFS) server daemon; NILFS2 file system; NTFS3 file system; OCFS2 file system; Proc file system; SMB network file system; UDF file system; XFS file system; Key management; BPF subsystem; Memory management; Software nodes and device properties; Glob pattern matching library; Memory Management; KVM subsystem; Mellanox drivers; Restartable sequences system call mechanism; Socket messages infrastructure; Network traffic control; Bluetooth subsystem; Netfilter; Networking core; Network sockets; TCP network protocol; io_uring subsystem; IPC subsystem; Audit subsystem; Perf events; Kernel fork() syscall; Locking primitives; Kernel module support; Scheduler infrastructure; Signal handling mechanism; Timer subsystem; Tracing infrastructure; Debug objects infrastructure; 6LoWPAN network protocol; IEEE 802 network protocols; 9P file system network protocol; B.A.T.M.A.N. meshing protocol; Ethernet bridge; Devlink API; HSR network protocol; IEEE802154.4 network protocol; IPv4 networking; IPv6 networking; XFRM subsystem; L2TP protocol; MAC80211 subsystem; IEEE 802.15.4 subsystem; Multipath TCP; NetLabel subsystem; Open vSwitch; Phonet protocol; Qualcomm IPC Router (QRTR); RDS protocol; SCTP protocol; SMC sockets; TIPC protocol; TLS protocol; Unix domain sockets; VMware vSockets driver; Wireless networking; eXpress Data Path; AppArmor security module; Linux Security Modules (LSM) Framework; Apple Onboard Audio ALSA driver; ALSA framework; FireWire sound drivers; HD-audio driver; Gravis UltraSound ALSA driver; C-Media CMI8x38 ALSA driver; ESS Solo-1 ALSA driver; ICE1712/ICE1724 (Envy24) ALSA driver; Yamaha YMFPCI ALSA driver; Wolfson Microelectronics audio codecs; SoundWire (SDCA) ASoC drivers; USB sound devices; Virtio sound driver
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. ( CVE-2025-10263 )
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
User-space API (UAPI);
Block layer subsystem;
Compute Acceleration Framework;
Compressed RAM block device driver;
Character device driver;
Hardware random number generator core;
CPU frequency scaling framework;
Hardware crypto device drivers;
Buffer Sharing and Synchronization framework;
Intel Stratix 10 firmware drivers;
CoreSight HW tracing drivers;
Input Device core drivers;
Input Device (Mouse) drivers;
Multiple devices driver;
Multifunction device drivers;
Ethernet bonding driver;
Mellanox network drivers;
MediaTek network drivers;
NVMEM (Non Volatile Memory) drivers;
Pin controllers subsystem;
x86 platform drivers;
System reset/shutdown drivers;
Power sequencing drivers;
Voltage and Current Regulator drivers;
Media staging drivers;
Realtek RTL8723BS SDIO drivers;
VME bus staging drivers;
Trusted Execution Environment drivers;
DesignWare USB3 driver;
Faraday FOTG210 USB2 dual-role controller driver;
USB Host Controller drivers;
Siemens ID Mouse USB driver;
IOWarrior USB driver;
LD Didactic USB driver;
LEGO USB Tower driver;
Intel USBIO USB I/O expander driver;
USS720 USB parallel port adapter driver;
MediaTek USB3 DRD driver;
USB Type-C Port Controller Manager driver;
USB Type-C Connector System Software Interface driver;
File systems infrastructure;
FUSE (File system in Userspace);
Network file system (NFS) client;
Network file system (NFS) server daemon;
SMB network file system;
Software nodes and device properties;
Glob pattern matching library;
Restartable sequences system call mechanism;
Socket messages infrastructure;
Network traffic control;
TCP network protocol;
Kernel fork() syscall;
Kernel module support;
Scheduler infrastructure;
Signal handling mechanism;
Tracing infrastructure;
Debug objects infrastructure;
6LoWPAN network protocol;
IEEE 802 network protocols;
9P file system network protocol;
B.A.T.M.A.N. meshing protocol;
HSR network protocol;
IEEE802154.4 network protocol;
IEEE 802.15.4 subsystem;
Qualcomm IPC Router (QRTR);
VMware vSockets driver;
AppArmor security module;
Linux Security Modules (LSM) Framework;
Apple Onboard Audio ALSA driver;
FireWire sound drivers;
Gravis UltraSound ALSA driver;
C-Media CMI8x38 ALSA driver;
ESS Solo-1 ALSA driver;
ICE1712/ICE1724 (Envy24) ALSA driver;
Yamaha YMFPCI ALSA driver;
Wolfson Microelectronics audio codecs;
SoundWire (SDCA) ASoC drivers;
After a standard system update you need to reboot your computer to make all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.
The problem can be corrected by updating your system to the following package versions:
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
Have additional questions?
Talk to a member of the team ›
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
