Race condition in Linux kernel - CVE-2025-10263
Published: July 14, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in broadcast TLBI completion in the arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory access patterns that rely on invalidated TLB entries to cause a denial of service.
The issue affects the completion of memory accesses translated by an invalidated TLB entry, while the TLB invalidation itself still occurs correctly.
Affected software
Red Hat Enterprise Linux Server - AUS
openEuler
Fedora
kernel (Red Hat package)
xen
kernel-tools
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
bpftool
kernel
Red Hat OpenShift Container Platform
How to mitigate CVE-2025-10263
kernel (Red Hat package) - addressed in versions 4.18.0-305.200.1.el8_4, 4.18.0-372.204.1.el8_6
xen - update to 4.20.4-1.fc43
Red Hat OpenShift Container Platform - update to 4.22.6
kernel-tools - update to 6.6.0-145.1.19.156
python3-perf-debuginfo - update to 6.6.0-145.1.19.156
python3-perf - update to 6.6.0-145.1.19.156
perf-debuginfo - update to 6.6.0-145.1.19.156
perf - update to 6.6.0-145.1.19.156
kernel-tools-devel - update to 6.6.0-145.1.19.156
kernel-tools-debuginfo - update to 6.6.0-145.1.19.156
kernel-source - update to 6.6.0-145.1.19.156
kernel-headers - update to 6.6.0-145.1.19.156
kernel-devel - update to 6.6.0-145.1.19.156
kernel-debugsource - update to 6.6.0-145.1.19.156
kernel-debuginfo - update to 6.6.0-145.1.19.156
bpftool-debuginfo - update to 6.6.0-145.1.19.156
bpftool - update to 6.6.0-145.1.19.156
kernel - update to 6.6.0-145.1.19.156
External References
- https://git.kernel.org/stable/c/1268c64e2bcb6e968152990e87bd10c440fcc9c0
- https://git.kernel.org/stable/c/1b47b1e1d8675fdf5f6e11e7fa19c704d8c6f5cd
- https://git.kernel.org/stable/c/4e7c80742e6dada9f8b9ad63f3a49c03af07ecb8
- https://git.kernel.org/stable/c/7c3ad9365079e716b57d2363d3081ee7680cc18e
- https://git.kernel.org/stable/c/8364384ae82fbffdf8968abaac3455ed854da18d
- https://git.kernel.org/stable/c/925058203229403008d77a52b1e63e2ae5f4a3cf
- https://git.kernel.org/stable/c/cfd391e74134db664feb499d43af286380b10ba8
- https://git.kernel.org/stable/c/d4fd4282204044fdedd1e42abbe70a9206f74ec0
- https://git.kernel.org/stable/c/e717a4d08779f1a28d6e0275e75040b12c33c753