Red Hat disclosed and remediated CVE-2025-10263, an Important Linux kernel flaw affecting multiple Arm processor families, including Cortex, Neoverse, and C1 lines. The bug stems from a race condition in TLBI operations during memory permission changes and can let a low-privileged local attacker write to memory owned by a higher exception level, leading to kernel privilege escalation, information disclosure, or even guest-to-hypervisor escape. Red Hat scored the issue CVSS 8.4 and linked it to CWE-266.
Fixes were rolled out across a broad set of Red Hat products, including RHEL 8, 9, and 10 kernel packages and OpenShift Container Platform 4.22.6. Advisories such as RHSA-2026:51746 for RHEL 9.4 SAP-related variants and RHSA-2026:55445 for RHEL 10.0 Extended Update Support included CVE-2025-10263 alongside other kernel vulnerabilities, while RHSA-2026:40764 delivered OpenShift updates covering the same issue. Red Hat said affected systems should be updated promptly and rebooted after applying the new kernel packages.

Get the actors, campaigns, and ATT&CK mapping behind it.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE-2025-10263 page, updating the public vulnerability record and fix status information.
Red Hat marked RHEL 10 kernel packages as fixed for CVE-2025-10263 in advisory RHSA-2026:34911.
Red Hat recorded the vulnerability description for CVE-2025-10263 in OSIDB/Bzimport, tracking the issue as an ARM processor flaw that may allow writes to higher exception level resources.
Red Hat published its CVE entry for CVE-2025-10263, describing an Important ARM/Linux kernel flaw caused by a TLBI race condition that can enable privilege escalation or guest-to-hypervisor escape.
Red Hat published RHSA-2026:55445, an Important kernel advisory for RHEL 10.0 Extended Update Support that fixes CVE-2025-10263 along with 10 other CVEs.
Red Hat marked RHEL 8.8 Update Services for SAP Solutions and Telecommunications Update Service kernel packages as fixed in RHSA-2026:52649.
Red Hat published RHSA-2026:51746, an Important kernel advisory for RHEL 9.4 Update Services for SAP Solutions and related variants that fixes CVE-2025-10263 among other vulnerabilities.
Red Hat marked RHEL 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages as fixed in RHSA-2026:49033.
Red Hat marked RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages as fixed in RHSA-2026:47248.
Red Hat released OpenShift Container Platform 4.22.6 as an Important security update that includes a fix for CVE-2025-10263 along with several other kernel vulnerabilities.
Red Hat marked both RHEL 8 kernel-rt and standard kernel packages as fixed for CVE-2025-10263 in advisories RHSA-2026:36348 and RHSA-2026:36349.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.