PT-2026-47727 · Arm+4 · Cortex-X1+23

CVE-2025-10263

·

Published

2026-06-09

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arm C1-Ultra (affected versions not specified) Arm C1-Premium (affected versions not specified) Arm Neoverse V3 & V3AE (affected versions not specified) Arm Neoverse V2 (affected versions not specified) Arm Neoverse V1 (affected versions not specified) Arm Neoverse-N2 (affected versions not specified) Arm Neoverse-N1 (affected versions not specified) Arm Cortex-X925 (affected versions not specified) Arm Cortex-X4 (affected versions not specified) Arm Cortex-X3 (affected versions not specified) Arm Cortex-X2 (affected versions not specified) Arm Cortex-X1 & X1C (affected versions not specified) Arm Cortex-A710 (affected versions not specified) Arm Cortex-A78, A78AE & A78C (affected versions not specified) Arm Cortex-A77 (affected versions not specified) Arm Cortex-A76 & A76A (affected versions not specified) NVIDIA Olympus (affected versions not specified)
Description A privilege escalation issue exists in various Arm CPU cores due to a timing condition during memory permission changes. Specifically, memory access completion is not guaranteed after Translation Lookaside Buffer (TLB) invalidation, which may allow writes to resources owned by a higher exception level. In the context of the Xen hypervisor, this could enable a guest system to write to memory belonging to the hypervisor.
Recommendations Apply the released Linux Kernel patches which implement a software workaround requiring additional TLB invalidation and a synchronization barrier.

Fix

LPE

DoS

Incorrect Privilege Assignment

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:34911
ALSA-2026:36018
ALSA-2026:36348
ALSA-2026:36349
BDU:2026-13733
CVE-2025-10263
ECHO-99F1-8BD8-D5F5
OESA-2026-2869
OESA-2026-3157
OESA-2026-3205
OESA-2026-3206
OPENSUSE-SU-2026:21388-1
RHSA-2026:34911
RHSA-2026:36018
RHSA-2026:36348
RHSA-2026:36349
RHSA-2026:47248
RHSA-2026:49031
RHSA-2026:49033
RHSA-2026:51603
RHSA-2026:51604
RHSA-2026:51746
RHSA-2026:52649
RHSA-2026:55445
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:2450-1
SUSE-SU-2026:2630-1
SUSE-SU-2026:2631-1
SUSE-SU-2026:2632-1
SUSE-SU-2026:2638-1
SUSE-SU-2026:2658-1
SUSE-SU-2026:2722-1
SUSE-SU-2026:2799-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

C1-Premium
C1-Ultra
Cortex-A710
Cortex-A76
Cortex-A77
Cortex-A78
Cortex-A78Ae
Cortex-A78C
Cortex-X1
Cortex-X1C
Cortex-X2
Cortex-X3
Cortex-X4
Cortex-X925
Freebsd
Linuxmint
Neoverse V1
Neoverse V2
Neoverse V3
Neoverse V3Ae
Neoverse N1
Neoverse N2
Rocky Linux
Ubuntu