Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities

A security issue was found in some Arm processors used in NVIDIA Tegra systems where the processor could incorrectly handle memory protection after changes, allowing a local attacker to write to protected memory or gain higher access rights. Additionally, many other security problems were fixed in various parts of the Linux kernel to prevent potential system compromise.

Published 18/9/2026, 8:50:47 amVerified 18/9/2026, 11:43:13 amRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

A security issue was found in some Arm processors used in NVIDIA Tegra systems where the processor could incorrectly handle memory protection after changes, allowing a local attacker to write to protected memory or gain higher access rights. Additionally, many other security problems were fixed in various parts of the Linux kernel to prevent potential system compromise.

Technical explanation

How the issue affects the environment

The primary vulnerability (CVE-2025-10263) involves certain Arm processors completing a broadcast translation lookaside buffer (TLB) invalidation before memory writes through the invalidated translation are globally observed. This timing flaw lets a local attacker write to memory locations after permission has been revoked, bypassing memory protections or escalating privileges. Besides ARM64 and ARM32 architectures, numerous kernel subsystems, driver modules, and architectures including PowerPC, x86, RISC-V, and others had security flaws addressed to mitigate potential exploitation vectors compromising system integrity.

Operational impact

Why teams should care

If exploited, attackers could bypass memory protection mechanisms or escalate privileges on affected systems, potentially compromising system security and sensitive data. This undermines both operational reliability and trust in systems running the vulnerable Linux kernel versions, such as those on NVIDIA Tegra hardware and Microsoft Azure environments.

Immediate action

Users and administrators should update their Linux kernel packages for NVIDIA Tegra systems to version 6.8.0-1035.38 or later, followed by a system reboot to apply the changes. Recompilation and reinstallation of third-party kernel modules are required due to ABI changes.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions6.8.0-1035.38

Temporary risk reduction

The advisory does not specify any workaround. Applying the update is required to address the vulnerabilities.

Evidence and validation checklist

  • Vulnerability discovered in Arm processors handling of broadcast TLB invalidation (CVE-2025-10263)
  • Multiple security issues discovered across numerous Linux kernel subsystems and drivers
  • Local attackers could exploit to bypass protections or escalate privileges
  • Update released to Linux kernel for NVIDIA Tegra systems to version 6.8.0-1035.38
  • Update instructions specify reboot and recompilation of third-party kernel modules due to ABI changes

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source