Linux distributors released security updates to fix multiple Linux kernel vulnerabilities that could let attackers bypass security restrictions, trigger denial-of-service conditions, obtain sensitive information, escalate privileges, execute arbitrary code, and gain access to affected systems. The advisory specifically highlighted CVE-2025-10263, a local race condition in Translation Lookaside Buffer invalidation operations rated CVSS 8.4, and CVE-2026-46316, a local guest-to-host escape vulnerability rated CVSS 7.0.
The notice said a proof-of-concept exploit for CVE-2026-46316 has been disclosed and is circulating in the wild, increasing the urgency for remediation. Red Hat and Ubuntu were identified as distributors providing fixes, and organizations were urged to validate and deploy patches promptly and monitor their vendors for any additional kernel-related updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The advisory stated that a proof-of-concept exploit for CVE-2026-46316 had been disclosed and existed in the wild. No specific date for the exploit disclosure was provided in the source content.
Linux released security updates on June 15, 2026 to address multiple kernel vulnerabilities that could enable security bypass, denial of service, information disclosure, privilege escalation, arbitrary code execution, and unauthorized system access. The notice specifically highlighted CVE-2025-10263 and CVE-2026-46316, and said Red Hat and Ubuntu were providing fixes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.