Notice USN-8818-2, published on September 25, 2026, says an update fixes vulnerabilities in the Linux kernel. The supplied text is an automatic translation of the Ubuntu Security feed; consult the original notice to confirm its wording and instructions for your system version.
A flaw in some Arm processors could allow memory writes to become globally observable after a broadcast TLB invalidation. Under certain conditions, a local attacker might write to memory after permission was revoked, bypassing memory protections or escalating privileges. The notice links this issue to CVE-2025-10263.
The notice also reports flaws in ARM64, InfiniBand and network drivers, TCM, exFAT, NFS client and server, B.A.T.M.A.N., IPv4, IPv6, Netfilter, and RDS subsystems. It lists CVEs from CVE-2026-53186 through CVE-2026-64091, including the intermediate identifiers enumerated in the notice. This list does not mean every system or configuration is affected in the same way.
To respond, identify the distribution and kernel version in use, consult the original notice and your distribution vendor’s guidance, and apply the recommended update. Then check that the packages are updated and that any required reboot or fix activation has been completed. Verify the result against official sources; do not treat this translated summary as a substitute for the notice.