CVE-2025-10263, a critical privilege escalation vulnerability affecting a wide range of Arm CPU cores, has been made public. The flaw allows writes to resources owned by a higher exception level via improper TLB invalidation. Affected cores include Arm's latest C1-Ultra and C1-Premium, multiple Neoverse server cores (V1/V2/V3, N1/N2), and many Cortex-X and Cortex-A series cores. A patch series for the Linux kernel has been posted, requiring an additional TLBI and DSB instruction after TLB invalidation operations. NVIDIA has also confirmed their Olympus cores in the Vera CPU are affected and submitted a follow-up mitigation patch.

1m read timeFrom phoronix.com
Post cover image
2.2K Impressions