Notice USN-8817-1, published on September 24, 2026 in the Ubuntu security feed, covers vulnerabilities fixed in a Linux kernel update. The source text is an automatic translation of the original notice.
A flaw involving some Arm processors could allow a local attacker to write to memory after the relevant permission was revoked. The issue could bypass memory protections or raise privileges and is identified as CVE-2025-10263.
The notice also lists issues in the ARM64, InfiniBand and network drivers, TCM, B.A.T.M.A.N., HSR, IPv4, IPv6, Netfilter and RDS subsystems. It cites 19 additional CVE identifiers: CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007 and CVE-2026-64091.
To assess relevance, consult the original Ubuntu security notice and confirm which update instructions apply to your distribution and the systems your organization uses. Check the CVE identifiers and technical details against original sources as well; this summary does not specify package versions or installation steps.
If you use AI to study the notice or prepare procedures, do not submit logs, configurations or other confidential data without authorization. Remove unnecessary data and ensure the material is permitted by your organization’s policy.