← Back to blog

Critical Linux Kernel Flaws Expose Systems to Privilege Escalation

Multiple high-severity vulnerabilities in the Linux kernel affect various architectures and expose systems to privilege escalation and memory protection bypasses.

TL;DR

  • Two critical flaws in Arm and AMD processors allow local attackers to escalate privileges.
  • The vulnerabilities stem from improper TLB invalidation and shared resource isolation failures.
  • Exploitation could lead to unauthorized memory access and instruction corruption.
  • A broad range of Linux subsystems and architectures are impacted by additional flaws.
  • Organizations using affected Oracle Cloud Infrastructure kernels should apply updates immediately.

Recent discoveries in the Linux kernel reveal serious security gaps that could allow attackers with local access to escalate privileges or bypass critical memory protections. These flaws primarily impact specific Arm and AMD processor lines but also extend across multiple architectures and kernel subsystems.

The vulnerabilities underscore the importance of timely patching, especially for infrastructure relying on customized or cloud-specific kernel builds such as those used by Oracle Cloud Infrastructure.

Hardware-Level Vulnerabilities

  • A flaw in certain Arm processors (CVE-2025-10263) allows writes to memory after permissions have been revoked due to premature TLB invalidation.
  • Some AMD Zen 2 processors fail to isolate shared resources in the operation cache, enabling potential corruption of privileged instructions (CVE-2025-54518).
  • Both issues can be exploited locally to achieve privilege escalation, undermining core system security assumptions.

Widespread Kernel Subsystem Impacts

  • Beyond hardware-specific bugs, multiple Linux kernel subsystems contain flaws that increase attack surface.
  • Affected areas include cryptographic APIs, UAPI interfaces, block layer operations, and architecture-specific components like x86, ARM64, and RISC-V.
  • These issues may allow attackers to compromise system integrity, leak sensitive data, or execute arbitrary code at elevated privileges.
  • The update addresses vulnerabilities across nearly all major CPU architectures supported by the Linux kernel.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.