CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8728-1: Linux kernel (GCP) vulnerabilities

unknownknown exploitedpublic exploitCVE-2025-10263CVE-2025-54518CVE-2026-43490CVE-2026-43492CVE-2026-43495CVE-2026-43496
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 platform drivers; - ARM64 architecture; - Cryptographic API; - PSP security protocol; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Auxiliary display drivers; - Drivers core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Ublk userspace block driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - Hardware random number generator core; - Clock framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - DPLL subsystem; - EDAC drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - Intel Stratix 10 firmware drivers; - FPGA Framework; - FWCTL subsystem; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - CoreSight HW tracing drivers; - I2C subsystem; - I3C su

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-09-07
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://ubuntu.com/security/notices/USN-8728-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-10263coverage & exploitation statusNVD · CVE.org
CVE-2025-54518coverage & exploitation statusNVD · CVE.org
CVE-2026-43490coverage & exploitation statusNVD · CVE.org
CVE-2026-43492coverage & exploitation statusNVD · CVE.org
CVE-2026-43495coverage & exploitation statusNVD · CVE.org
CVE-2026-43496coverage & exploitation statusNVD · CVE.org
CVE-2026-43497coverage & exploitation statusNVD · CVE.org
CVE-2026-43498coverage & exploitation statusNVD · CVE.org
CVE-2026-43502coverage & exploitation statusNVD · CVE.org
CVE-2026-45834coverage & exploitation statusNVD · CVE.org
CVE-2026-45835coverage & exploitation statusNVD · CVE.org
CVE-2026-45836coverage & exploitation statusNVD · CVE.org
CVE-2026-45837coverage & exploitation statusNVD · CVE.org
CVE-2026-45838coverage & exploitation statusNVD · CVE.org
CVE-2026-45839coverage & exploitation statusNVD · CVE.org
CVE-2026-45840coverage & exploitation statusNVD · CVE.org
CVE-2026-45841coverage & exploitation statusNVD · CVE.org
CVE-2026-45842coverage & exploitation statusNVD · CVE.org
CVE-2026-45843coverage & exploitation statusNVD · CVE.org
CVE-2026-45844coverage & exploitation statusNVD · CVE.org
CVE-2026-45845coverage & exploitation statusNVD · CVE.org
CVE-2026-45846coverage & exploitation statusNVD · CVE.org
CVE-2026-46104coverage & exploitation statusNVD · CVE.org
CVE-2026-46105coverage & exploitation statusNVD · CVE.org
CVE-2026-46106coverage & exploitation statusNVD · CVE.org
CVE-2026-46107coverage & exploitation statusNVD · CVE.org
CVE-2026-46108coverage & exploitation statusNVD · CVE.org
CVE-2026-46109coverage & exploitation statusNVD · CVE.org
CVE-2026-46110coverage & exploitation statusNVD · CVE.org
CVE-2026-46111coverage & exploitation statusNVD · CVE.org
CVE-2026-46112coverage & exploitation statusNVD · CVE.org
CVE-2026-46113coverage & exploitation statusNVD · CVE.org
CVE-2026-46114coverage & exploitation statusNVD · CVE.org
CVE-2026-46115coverage & exploitation statusNVD · CVE.org
CVE-2026-46116coverage & exploitation statusNVD · CVE.org
CVE-2026-46117coverage & exploitation statusNVD · CVE.org
CVE-2026-46118coverage & exploitation statusNVD · CVE.org
CVE-2026-46119coverage & exploitation statusNVD · CVE.org
CVE-2026-46120coverage & exploitation statusNVD · CVE.org
CVE-2026-46121coverage & exploitation statusNVD · CVE.org
CVE-2026-46122coverage & exploitation statusNVD · CVE.org
CVE-2026-46123coverage & exploitation statusNVD · CVE.org
CVE-2026-46124coverage & exploitation statusNVD · CVE.org
CVE-2026-46125coverage & exploitation statusNVD · CVE.org
CVE-2026-46126coverage & exploitation statusNVD · CVE.org
CVE-2026-46127coverage & exploitation statusNVD · CVE.org
CVE-2026-46128coverage & exploitation statusNVD · CVE.org
CVE-2026-46129coverage & exploitation statusNVD · CVE.org

+1369 more CVEs referenced in this advisory.

More from Ubuntu Security Notices