CVE-2026-53354

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/07/2026
Last modified:
22/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> arm64: errata: Mitigate TLBI errata on various Arm CPUs<br /> <br /> A number of CPUs developed by Arm suffer from errata whereby a broadcast<br /> TLBI;DSB sequence may complete before the global observation of writes<br /> which are translated by an affected TLB entry.<br /> <br /> These errata ONLY affect the completion of memory accesses which have<br /> been translated by an invalidated TLB entry, and these errata DO NOT<br /> affect the actual invalidation of TLB entries. TLB entries are removed<br /> correctly.<br /> <br /> This issue has been assigned CVE ID CVE-2025-10263.<br /> <br /> To mitigate this issue, Arm recommends that software follows any<br /> affected TLBI;DSB sequence with an additional TLBI;DSB, which will<br /> ensure that all memory write effects affected by the first TLBI have<br /> been globally observed. The additional TLBI can use any operation that<br /> is broadcast to affected CPUs, and the additional DSB can use any option<br /> that is sufficient to complete the additional TLBI.<br /> <br /> The ARM64_WORKAROUND_REPEAT_TLBI workaround is sufficient to mitigate<br /> the issue. Enable this workaround for affected CPUs, and update the<br /> silicon errata documentation accordingly.<br /> <br /> Note that due to the manner in which Arm develops IP and tracks errata,<br /> some CPUs share a common erratum number.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.7 (including) 5.10.259 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.210 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.1 (including) 7.1.1 (excluding)