Bulletin USN-8818-1, published on September 24, 2026, says an update fixes several Linux kernel security flaws. One, CVE-2025-10263, affects some Arm processors: a broadcast TLB invalidation could complete before certain memory writes were observed globally. A local attacker could then write to memory after permission had been revoked, bypassing memory protections or raising privileges.
The notice also cites flaws in ARM64, InfiniBand and network drivers, TCM, exFAT, the NFS client and server daemon, B.A.T.M.A.N., IPv4, IPv6, Netfilter, and RDS. Listed identifiers include CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, and CVE-2026-64091. Consult the original Ubuntu security notice and check whether the update applies to your version; this summary does not replace official instructions.