It was discovered that the i.MX clock driver in the Linux kernel did not
properly handle certain memory allocation failure conditions, leading to a
null pointer dereference vulnerability. A local attacker could possibly use
this to cause a denial of service (system crash). (CVE-2022-3114)
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- User-space API (UAPI);
- ARM32 architecture;
- MIPS architecture;
- PowerPC architecture;
- RISC-V architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- ACPI drivers;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- Drivers core;
- DRBD Distributed Replicated Block Device drivers;
- Rados block device (RBD) driver;
- Bluetooth drivers;
- Cdrom driver;
- Character device driver;
- Hardware random number generator core;
- TPM device driver;
- Data acquisition framework and drivers;
- CPU frequency scaling framework;
- Hardware crypto device drivers;
- DAX dirext access to differentiated memory framework;
- DMA engine subsystem;
- FireWire subsystem;
- Arm Firmware Framework for ARMv8-A(FFA);
- ARM SCMI message protocol;
- Intel Stratix 10 firmware drivers;
- FPGA Framework;
- GPIO subsystem;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- Intel Trace Hub HW tracing drivers;
- I2C subsystem;
- IIO subsystem;
- IIO ADC drivers;
- IIO Magnetometer...