It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- User-space API (UAPI);
- Kernel build system;
- ARM32 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Cryptographic API;
- Intel NPU Driver;
- Compute Acceleration Framework;
- ACPI drivers;
- Drivers core;
- DRBD Distributed Replicated Block Device drivers;
- Rados block device (RBD) driver;
- Ublk userspace block driver;
- Compressed RAM block device driver;
- Bluetooth drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- FPGA Framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- I2C subsystem;
- I3C subsystem;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Mouse) drivers;
- IOMMU subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Mellanox network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- MediaTek network drivers;
- NVME drivers;
- Operating Performance Points (OPP) driver;
- PCI subsystem;
- PTP clock framework;
- RPMSG subsystem;
- SCSI subsystem;
- SoundWire subsystem;
- SPI subsystem;
- Greybus lights staging drivers;
- Media staging drivers;
- NVIDIA Tegra embedded controller (NVEC) staging driver;
- Realtek RTL8723BS...