USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities
A security issue was found in some Arm processors used in NVIDIA Tegra systems where the processor could incorrectly handle memory protection after changes, allowing a local attacker to write to protected memory or gain higher access rights. Additionally, many other security problems were fixed in various parts of the Linux kernel to prevent potential system compromise.
Published 18/9/2026, 8:50:47 amVerified 18/9/2026, 11:43:13 amRevision 1
In plain language
What this advisory means
A security issue was found in some Arm processors used in NVIDIA Tegra systems where the processor could incorrectly handle memory protection after changes, allowing a local attacker to write to protected memory or gain higher access rights. Additionally, many other security problems were fixed in various parts of the Linux kernel to prevent potential system compromise.
Technical explanation
How the issue affects the environment
The primary vulnerability (CVE-2025-10263) involves certain Arm processors completing a broadcast translation lookaside buffer (TLB) invalidation before memory writes through the invalidated translation are globally observed. This timing flaw lets a local attacker write to memory locations after permission has been revoked, bypassing memory protections or escalating privileges. Besides ARM64 and ARM32 architectures, numerous kernel subsystems, driver modules, and architectures including PowerPC, x86, RISC-V, and others had security flaws addressed to mitigate potential exploitation vectors compromising system integrity.
Operational impact
Why teams should care
If exploited, attackers could bypass memory protection mechanisms or escalate privileges on affected systems, potentially compromising system security and sensitive data. This undermines both operational reliability and trust in systems running the vulnerable Linux kernel versions, such as those on NVIDIA Tegra hardware and Microsoft Azure environments.
Immediate action
Users and administrators should update their Linux kernel packages for NVIDIA Tegra systems to version 6.8.0-1035.38 or later, followed by a system reboot to apply the changes. Recompilation and reinstallation of third-party kernel modules are required due to ABI changes.
Affected and fixed releases
Affected versionsConfirm in the official vendor advisory
Fixed versions6.8.0-1035.38
Temporary risk reduction
The advisory does not specify any workaround. Applying the update is required to address the vulnerabilities.
Evidence and validation checklist
Vulnerability discovered in Arm processors handling of broadcast TLB invalidation (CVE-2025-10263)
Multiple security issues discovered across numerous Linux kernel subsystems and drivers
Local attackers could exploit to bypass protections or escalate privileges
Update released to Linux kernel for NVIDIA Tegra systems to version 6.8.0-1035.38
Update instructions specify reboot and recompilation of third-party kernel modules due to ABI changes
Authoritative reference
Ubuntu Security Notices
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.