Notice USN-8818-6, published on October 2, 2026, reports that some Arm processors could complete a broadcast TLB invalidation before writes made through the invalidated translation were globally observed. A local attacker could then write to memory after permission was revoked, bypass memory protections, or escalate privileges (CVE-2025-10263). The text also describes other flaws that could allow system compromise.
The cited update covers ARM64, InfiniBand, network drivers, TCM, exFAT, the NFS client and server daemon, B.A.T.M.A.N., IPv4, IPv6, Netfilter, and RDS. The other references are CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, and CVE-2026-64091. Consult the original Ubuntu Security notice, USN-8818-6, to verify the details and check the applicable guidance for affected systems.