CVE-2025-10263

Aliases:DEBIAN-CVE-2025-10263UBUNTU-CVE-2025-10263ALPINE-CVE-2025-10263
Awaiting Analysis
Published: 09 Jun 2026, 09:23
Last modified:04 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (cve.org)
EPSS Score
0.57% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jun 2026, 09:23
Published
Vulnerability first disclosed
04 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

CVSS Metrics

  • v4.0HIGHScore: 7.3CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.57% Percentile: 46%

Techniques & Countermeasures

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

  • CWE-266Incorrect Privilege Assignment

    A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Systems

  • alpinexen

    < 4.18.5-r9 | < 4.19.5-r4 | < 4.20.3-r4 | < 4.20.3-r4 | < 4.21.1-r6

  • armc1-premium

    All versions

  • armc1-ultra

    All versions

  • armcortex-a710

    All versions

  • armcortex-a76

    All versions

  • armcortex-a76ae

    All versions

  • armcortex-a77

    All versions

  • armcortex-a78

    All versions

  • armcortex-a78ae

    All versions

  • armcortex-a78c

    All versions

  • armcortex-x1

    All versions

  • armcortex-x1c

    All versions

  • armcortex-x2

    All versions

  • armcortex-x3

    All versions

  • armcortex-x4

    All versions

  • armcortex-x925

    All versions

  • armneoverse n1

    All versions

  • armneoverse n2

    All versions

  • armneoverse v1

    All versions

  • armneoverse v3

    All versions

  • armneoverse v3ae

    All versions

  • debianlinux

    < 5.10.259-1 | < 6.1.176-1 | < 6.12.94-1 | < 7.0.13-1

  • debianlinux-6.1

    < 6.1.176-1~deb11u1

  • debianxen

    all | all | < 4.20.3+127-gc42374a105-0+deb13u1 | < 4.20.3+127-gc42374a105-1

  • ubuntulinux

    all | all | all | all | < 7.0.0-31.31

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | all | all | all | < 7.0.0-1012.12

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    all

  • ubuntulinux-aws-7.0

    all | < 7.0.0-1012.12~24.04.1

  • ubuntulinux-aws-fips

    all

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | all | all | all

  • ubuntulinux-azure-4.15

    all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

Showing first 50 affected entries in server-rendered view.

References (42)