EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

USN-8728-2: Linux kernel (Azure) vulnerabilities

Official source
EudorIA operational summary

What it means

Priority 85/100

Ubuntu ha rilasciato un aggiornamento di sicurezza (USN-8728-2) per il kernel Linux Azure, correggendo diverse vulnerabilità. Tra queste, CVE-2025-10263 riguarda alcuni processori Arm e permette a un attaccante locale di bypassare le protezioni della memoria o elevare privilegi. CVE-2025-54518 riguarda alcuni processori AMD Zen 2 e permette a un attaccante locale di corrompere istruzioni eseguite a livello di privilegio più alto, portando a un elevamento di privilegi. L'aggiornamento riguarda diversi sottosistemi del kernel, tra cui driver, architetture e framework. L'aggiornamento richiede un riavvio e la reinstallazione di moduli kernel terzi.

Why it matters

Per le PMI italiane che utilizzano sistemi basati su Linux Azure, queste vulnerabilità rappresentano un rischio significativo per la sicurezza dei dati e delle operazioni. L'elevazione di privilegi e la possibilità di bypassare le protezioni della memoria possono portare a compromissioni critiche, con impatti diretti sulla continuità operativa e sulla conformità normativa.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità del kernel.
  • Miglioramento della protezione contro attacchi locali e remoti.
  • Garanzia di conformità e continuità operativa.
  • Sicurezza incrementata grazie all'aggiornamento dei driver e del kernel.
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteMonitoraggio / SIEMFirewall NGFW / IPSBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

Ubuntu Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 platform drivers; - ARM64 architecture; - Cryptographic API; - PSP security protocol; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Auxiliary display drivers; - Drivers core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Ublk userspace block driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - Hardware random number generator core; - Clock framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - DPLL subsystem; - EDAC drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - Intel Stra

Source
Ubuntu Security Notices
Publishing entity
Ubuntu Security
Entity type
vendor security
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 15:19
MITRE ATT&CK
T1059
CVE
CVE-2025-10263, CVE-2025-54518
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source