Ampere Computing Logo
Ampere Computing Logo
Hero Image

ARM CVE-2025-10263

Bulletin ID: AMP-SB-0008


Problem Statement and Impact
A vulnerability in Ampere® Altra® and Altra® Max processors may permit the use of stale Stage 1 and/or Stage 2 translation table entries under certain conditions.

Mitigation requires Trusted Firmware-A and Hafnium firmware patches distributed by Ampere along with operating system patches.

Arm has submitted patches to the Linux Kernel and Trusted Firmware-A to mitigate this issue.Arm has submitted patches to the Linux Kernel and Trusted Firmware-A to mitigate this issue.

Arm reported this security issue to Ampere Computing.

Severity

High: Where local access to the system requires authentication

CVSS score: 8.8

[CVSS (version 3.1) 8.8/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H]

Critical: Where the system permits local untrusted code execution

CVSS score: 9.3

[CVSS (version 3.1) 9.3/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H]

Fixed in

Ampere Altra Family SRP 2.10j and later

Recommendations

Update firmware to SRP 2.10j or later.

Update operating systems/hypervisor.

References

  • Documentation - Arm Developer
  • https://www.cve.org/CVERecord?id=CVE-2025-10263
Created At : December 18th 2023, 5:11:51 pm
Last Updated At : June 9th 2026, 6:27:40 pm
Ampere Logo

Ampere Computing LLC

4655 Great America Parkway Suite 601

Santa Clara, CA 95054

image
image
image
image
image
 |  |  | 
© 2025 Ampere Computing LLC. All rights reserved. Ampere, Altra and the A and Ampere logos are registered trademarks or trademarks of Ampere Computing.
This site runs on Ampere Processors.