Notice USN-8728-3, published on September 29, 2026 in the Ubuntu Security feed, concerns Linux kernel vulnerabilities. The text says some flaws could allow memory corruption or system compromise and recommends applying the applicable update.
Among the cases described, CVE-2025-10263 concerns Arm processors where a TLB invalidation could complete before certain memory writes were observed globally. Under some conditions, a local attacker could write to memory after permission had been revoked. CVE-2025-54518 concerns some AMD Zen 2 processors and incorrect isolation of shared resources in the operations cache, potentially corrupting instructions executed at a higher privilege level.
The notice also lists fixes across many components: architectures including ARM64, ARM32, MIPS, PowerPC, RISC-V, S390, and x86, as well as networking, storage, Bluetooth, GPU, drivers, cryptography, and power management. Consult the original Ubuntu security notice for details, affected packages, and the update applicable to your system; also confirm the information through your distribution’s official update channels.
Before updating production systems, identify the versions and configurations in use, assess operational impact, and follow your organization’s change process. If you use AI to summarize the notice or plan deployment, share only necessary excerpts and remove names, email addresses, identifiers, and other internal data. Verify technical recommendations against the notice and official documentation, not only the model’s response.