CVE-2026-53145
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Drivers core; - Compressed RAM block device driver; - Bluetooth drivers; - Character device driver; - Hardware random number generator core; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - Intel Stratix 10 firmware drivers; - FPGA Framework; - GPIO subsystem; - GPU drivers; - HID subsystem; - CoreSight HW tracing drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - Fastrpc Driver; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - MediaTek network drivers; - NTB driver; - NVME drivers; - NVMEM (Non Volatile Memory) drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - System reset/shutdown drivers; - Power sequencing drivers; - PTP clock framework; - Voltage and Current Regulator drivers; - RPMSG subsystem; - SLIMbus drivers; - SPI subsystem; - Media staging drivers; - Realtek RTL8723BS
⚡ Watch CVE-2026-53145
Get an email if CVE-2026-53145 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownexploitedUSN-8727-1: Linux kernel (OEM) vulnerabilitiesubuntu · 2026-09-07
- unknownexploitedUSN-8726-1: Linux kernel vulnerabilitiesubuntu · 2026-09-07
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-53145)