Security Advisory Desk
unratedQCS priority 70/100Ubuntu

USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilities

A vulnerability was found in some Arm processors used by Raspberry Pi devices running the Linux kernel. These processors could incorrectly allow memory writes after access rights were revoked, potentially letting a local attacker bypass memory protections or gain higher privileges. Additionally, many other security issues affecting various parts of the Linux kernel were discovered. Updates have been issued to fix these vulnerabilities in Ubuntu's Raspberry Pi Linux kernel packages.

Published 18/9/2026, 8:43:58 amVerified 19/9/2026, 6:55:45 pmRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

A vulnerability was found in some Arm processors used by Raspberry Pi devices running the Linux kernel. These processors could incorrectly allow memory writes after access rights were revoked, potentially letting a local attacker bypass memory protections or gain higher privileges. Additionally, many other security issues affecting various parts of the Linux kernel were discovered. Updates have been issued to fix these vulnerabilities in Ubuntu's Raspberry Pi Linux kernel packages.

Technical explanation

How the issue affects the environment

The issue arises due to some Arm processors performing a broadcast Translation Lookaside Buffer (TLB) invalidation before memory writes through the invalidated translation are globally observed. This timing flaw may let a local attacker write to memory after permissions were revoked, effectively bypassing memory protection mechanisms or escalating privileges. Besides this, multiple security vulnerabilities were identified across numerous Linux kernel subsystems, including ARM64, ARM32, x86 architectures, cryptographic APIs, device drivers, filesystems, networking components, and more. Applying the updated Linux kernel packages addresses these flaws.

Operational impact

Why teams should care

If exploited, attackers with local access could bypass memory protections or escalate their privileges on affected Raspberry Pi Linux systems. This may lead to unauthorized data access, system compromise, or denial of service. The wide range of affected kernel components indicates a broad security risk that could impact system stability and trustworthiness. Organizations using Ubuntu Linux on Raspberry Pi and other platforms should update promptly to mitigate these risks.

Immediate action

Update your system's Linux kernel packages to version 7.0.0-1019.19 or later and reboot the computer to apply the security fixes. Note that this update includes an ABI (Application Binary Interface) change requiring recompilation and reinstallation of all third-party kernel modules for compatibility.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions7.0.0-1019.19

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Ubuntu Security Notice USN-8726-2 documents the ARM TLB invalidation vulnerability CVE-2025-10263.
  • The notice lists numerous subsystems fixed, covering many CVEs across Linux kernel components.
  • The update requiring kernel version 7.0.0-1019.19 includes the fixes and requires reboot and module recompilation.
  • The source confirms the vulnerability affects Raspberry Pi Linux kernel in Ubuntu 26.04 LTS.

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source