Canonical Security Advisories · May 2022 — Canonical Security Advisories
83 advisories 194 CVEs 3 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2022-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-5451-1

USNExploitedCISA KEV listedCRITICAL2022-05-31

influxdb vulnerability

CVEs:CVE-2019-20933

Affected products

ProductStatusVendorPackageEcosystem
influxdb affected Ubuntu:20.04:LTS influxdb —
influxdb affected Ubuntu:18.04:LTS influxdb —
Upstream advisory

USN-5434-1

USNExploitedVulnCheck KEV listedNONE2022-05-23

firefox vulnerabilities

CVEs:CVE-2022-1529CVE-2022-1802

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:18.04:LTS firefox —
firefox affected Ubuntu:20.04:LTS firefox —
Upstream advisory

USN-5422-1

USNWeaponized exploitCRITICAL2022-05-16

libxml2 vulnerabilities

CVEs:CVE-2022-23308CVE-2022-29824

Affected products

ProductStatusVendorPackageEcosystem
libxml2 affected Ubuntu:22.04:LTS libxml2 —
libxml2 affected Ubuntu:Pro:16.04:LTS libxml2 —
libxml2 affected Ubuntu:Pro:14.04:LTS libxml2 —
libxml2 affected Ubuntu:18.04:LTS libxml2 —
libxml2 affected Ubuntu:20.04:LTS libxml2 —
Upstream advisory

USN-4961-2

USNWeaponized exploitNONE2022-05-19

python-pip vulnerability

CVEs:CVE-2021-3572

Affected products

ProductStatusVendorPackageEcosystem
python-pip affected Ubuntu:Pro:14.04:LTS python-pip —
python-pip affected Ubuntu:Pro:18.04:LTS python-pip —
python-pip affected Ubuntu:Pro:16.04:LTS python-pip —
Upstream advisory

USN-5442-1

USNWeaponized exploitHIGH2022-05-24

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gke, linux-gke-5.4, linux-hwe-5.4, linux-ibm, linux-kvm vulnerabilities

CVEs:CVE-2022-1116CVE-2022-29581CVE-2022-30594

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux —
linux-aws affected Ubuntu:20.04:LTS linux-aws —
linux-aws-5.4 affected Ubuntu:18.04:LTS linux-aws-5.4 —
linux-azure affected Ubuntu:20.04:LTS linux-azure —
linux-azure-5.4 affected Ubuntu:18.04:LTS linux-azure-5.4 —
linux-azure-fde affected Ubuntu:20.04:LTS linux-azure-fde —
linux-gcp affected Ubuntu:20.04:LTS linux-gcp —
linux-gke affected Ubuntu:20.04:LTS linux-gke —
linux-gke-5.4 affected Ubuntu:18.04:LTS linux-gke-5.4 —
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4 —
linux-ibm affected Ubuntu:20.04:LTS linux-ibm —
linux-kvm affected Ubuntu:20.04:LTS linux-kvm —
Upstream advisory

USN-5443-1

USNWeaponized exploitHIGH2022-05-24

linux, linux-aws, linux-aws-hwe, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke, linux-hwe, linux-hwe-5.13, linux-ibm, linux-kvm, linux-lowlatency, linux-oracle, linux-raspi, linux-raspi2, linux-snapdragon vulnerabilities

CVEs:CVE-2022-29581CVE-2022-30594

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:18.04:LTS linux —
linux affected Ubuntu:22.04:LTS linux —
linux-aws affected Ubuntu:22.04:LTS linux-aws —
linux-aws affected Ubuntu:18.04:LTS linux-aws —
linux-aws-5.13 affected Ubuntu:20.04:LTS linux-aws-5.13 —
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe —
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure —
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure —
linux-azure affected Ubuntu:22.04:LTS linux-azure —
linux-azure-4.15 affected Ubuntu:18.04:LTS linux-azure-4.15 —
linux-azure-5.13 affected Ubuntu:20.04:LTS linux-azure-5.13 —
linux-gcp affected Ubuntu:22.04:LTS linux-gcp —
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp —
linux-gcp-4.15 affected Ubuntu:18.04:LTS linux-gcp-4.15 —
linux-gke affected Ubuntu:22.04:LTS linux-gke —
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe —
linux-hwe-5.13 affected Ubuntu:20.04:LTS linux-hwe-5.13 —
linux-ibm affected Ubuntu:22.04:LTS linux-ibm —
linux-kvm affected Ubuntu:18.04:LTS linux-kvm —
linux-kvm affected Ubuntu:22.04:LTS linux-kvm —
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency —
linux-oracle affected Ubuntu:22.04:LTS linux-oracle —
linux-oracle affected Ubuntu:Pro:16.04:LTS linux-oracle —
linux-oracle affected Ubuntu:18.04:LTS linux-oracle —
linux-raspi affected Ubuntu:22.04:LTS linux-raspi —
linux-raspi2 affected Ubuntu:18.04:LTS linux-raspi2 —
linux-snapdragon affected Ubuntu:18.04:LTS linux-snapdragon —
Upstream advisory

USN-5426-1

USNWeaponized exploitHIGH2022-05-17

needrestart vulnerability

CVEs:CVE-2022-30688

Affected products

ProductStatusVendorPackageEcosystem
needrestart affected Ubuntu:22.04:LTS needrestart —
needrestart affected Ubuntu:20.04:LTS needrestart —
needrestart affected Ubuntu:18.04:LTS needrestart —
Upstream advisory

USN-4781-1

USNActive exploitation (sightings)HIGH2022-05-25

slurm-llnl vulnerabilities

CVEs:CVE-2016-10030CVE-2017-15566CVE-2018-7033CVE-2018-10995CVE-2019-6438CVE-2020-12693CVE-2020-27745CVE-2020-27746CVE-2021-31215

Affected products

ProductStatusVendorPackageEcosystem
slurm-llnl affected Ubuntu:Pro:18.04:LTS slurm-llnl —
slurm-llnl affected Ubuntu:Pro:16.04:LTS slurm-llnl —
slurm-llnl affected Ubuntu:Pro:14.04:LTS slurm-llnl —
slurm-llnl affected Ubuntu:Pro:20.04:LTS slurm-llnl —
Upstream advisory

USN-5430-1

USNActive exploitation (sightings)NONE2022-05-18

gnome-control-center vulnerability

CVEs:CVE-2022-1736

Affected products

ProductStatusVendorPackageEcosystem
gnome-control-center affected Ubuntu:22.04:LTS gnome-control-center —
Upstream advisory

UBUNTU-CVE-2021-22573

USNActive exploitation (sightings)HIGH2022-05-03

CVEs:CVE-2021-22573

Affected products

ProductStatusVendorPackageEcosystem
google-oauth-client-java affected Ubuntu:22.04:LTS google-oauth-client-java —
google-oauth-client-java affected Ubuntu:24.04:LTS google-oauth-client-java —
google-oauth-client-java affected Ubuntu:25.10 google-oauth-client-java —
Upstream advisory

USN-5402-1

USNCoalition ESS > 63%HIGH2022-05-04

openssl, openssl1.0 vulnerabilities

CVEs:CVE-2022-1292CVE-2022-1343CVE-2022-1434CVE-2022-1473

Affected products

ProductStatusVendorPackageEcosystem
openssl affected Ubuntu:20.04:LTS openssl —
openssl affected Ubuntu:22.04:LTS openssl —
openssl affected Ubuntu:18.04:LTS openssl —
openssl1.0 affected Ubuntu:18.04:LTS openssl1.0 —
Upstream advisory

USN-5424-2

USNPoC exploitCRITICAL2022-05-19

openldap vulnerability

CVEs:CVE-2022-29155

Affected products

ProductStatusVendorPackageEcosystem
openldap affected Ubuntu:Pro:16.04:LTS openldap —
openldap affected Ubuntu:Pro:14.04:LTS openldap —
Upstream advisory

USN-5424-1

USNPoC exploitCRITICAL2022-05-17

openldap vulnerability

CVEs:CVE-2022-29155

Affected products

ProductStatusVendorPackageEcosystem
openldap affected Ubuntu:20.04:LTS openldap —
openldap affected Ubuntu:22.04:LTS openldap —
openldap affected Ubuntu:18.04:LTS openldap —
Upstream advisory

USN-5440-1

USNPoC exploitHIGH2022-05-24

postgresql-10, postgresql-12, postgresql-13, postgresql-14 vulnerability

CVEs:CVE-2022-1552

Affected products

ProductStatusVendorPackageEcosystem
postgresql-10 affected Ubuntu:18.04:LTS postgresql-10 —
postgresql-12 affected Ubuntu:20.04:LTS postgresql-12 —
postgresql-14 affected Ubuntu:22.04:LTS postgresql-14 —
Upstream advisory

USN-5425-1

USNPoC exploit2022-05-17

pcre3 vulnerabilities

CVEs:CVE-2019-20838CVE-2020-14155

Affected products

ProductStatusVendorPackageEcosystem
pcre3 affected Ubuntu:20.04:LTS pcre3 —
pcre3 affected Ubuntu:Pro:16.04:LTS pcre3 —
pcre3 affected Ubuntu:22.04:LTS pcre3 —
pcre3 affected Ubuntu:18.04:LTS pcre3 —
pcre3 affected Ubuntu:Pro:14.04:LTS pcre3 —
Upstream advisory

USN-5404-2

USNPoC exploitHIGH2022-05-24

rsyslog vulnerability

CVEs:CVE-2022-24903

Affected products

ProductStatusVendorPackageEcosystem
rsyslog affected Ubuntu:Pro:16.04:LTS rsyslog —
Upstream advisory

USN-5404-1

USNPoC exploitHIGH2022-05-05

rsyslog vulnerability

CVEs:CVE-2022-24903

Affected products

ProductStatusVendorPackageEcosystem
rsyslog affected Ubuntu:20.04:LTS rsyslog —
rsyslog affected Ubuntu:18.04:LTS rsyslog —
rsyslog affected Ubuntu:22.04:LTS rsyslog —
Upstream advisory

USN-5403-1

USNPoC exploitCRITICAL2022-05-05

sqlite3 vulnerability

CVEs:CVE-2021-36690

Affected products

ProductStatusVendorPackageEcosystem
sqlite3 affected Ubuntu:20.04:LTS sqlite3 —
sqlite3 affected Ubuntu:18.04:LTS sqlite3 —
Upstream advisory

USN-5179-2

USNPoC exploitHIGH2022-05-10

busybox vulnerability

CVEs:CVE-2021-28831

Affected products

ProductStatusVendorPackageEcosystem
busybox affected Ubuntu:Pro:16.04:LTS busybox —
Upstream advisory

USN-5408-1

USNPoC exploitCRITICAL2022-05-10

dnsmasq vulnerability

CVEs:CVE-2022-0934

Affected products

ProductStatusVendorPackageEcosystem
dnsmasq affected Ubuntu:Pro:16.04:LTS dnsmasq —
dnsmasq affected Ubuntu:Pro:14.04:LTS dnsmasq —
dnsmasq affected Ubuntu:20.04:LTS dnsmasq —
dnsmasq affected Ubuntu:22.04:LTS dnsmasq —
dnsmasq affected Ubuntu:18.04:LTS dnsmasq —
Upstream advisory

USN-5418-1

USNPoC exploitHIGH2022-05-12

linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-snapdragon vulnerabilities

CVEs:CVE-2021-26401CVE-2022-23036CVE-2022-23037CVE-2022-23038CVE-2022-23039CVE-2022-23040CVE-2022-23042CVE-2022-24958CVE-2022-25258CVE-2022-25375CVE-2022-26490CVE-2022-26966CVE-2022-27223

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:18.04:LTS linux —
linux-aws affected Ubuntu:18.04:LTS linux-aws —
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe —
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure —
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure —
linux-azure-4.15 affected Ubuntu:18.04:LTS linux-azure-4.15 —
linux-dell300x affected Ubuntu:18.04:LTS linux-dell300x —
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp —
linux-gcp-4.15 affected Ubuntu:18.04:LTS linux-gcp-4.15 —
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe —
linux-kvm affected Ubuntu:18.04:LTS linux-kvm —
linux-oracle affected Ubuntu:18.04:LTS linux-oracle —
linux-oracle affected Ubuntu:Pro:16.04:LTS linux-oracle —
linux-snapdragon affected Ubuntu:18.04:LTS linux-snapdragon —
Upstream advisory

USN-5417-1

USNPoC exploitHIGH2022-05-12

linux, linux-aws, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities

CVEs:CVE-2021-26401CVE-2022-20008CVE-2022-25258CVE-2022-25375CVE-2022-26490CVE-2022-26966CVE-2022-27223CVE-2022-29156

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-5.13 affected Ubuntu:20.04:LTS linux-aws-5.13 —
linux-azure-5.13 affected Ubuntu:20.04:LTS linux-azure-5.13 —
linux-gcp-5.13 affected Ubuntu:20.04:LTS linux-gcp-5.13 —
linux-hwe-5.13 affected Ubuntu:20.04:LTS linux-hwe-5.13 —
Upstream advisory

USN-5415-1

USNPoC exploitHIGH2022-05-12

linux, linux-aws, linux-azure, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gcp-5.4, linux-gke, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2020-27820CVE-2021-26401CVE-2022-1016CVE-2022-20008CVE-2022-25258CVE-2022-25375CVE-2022-26490CVE-2022-27223

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux —
linux-aws affected Ubuntu:20.04:LTS linux-aws —
linux-azure affected Ubuntu:20.04:LTS linux-azure —
linux-azure-5.4 affected Ubuntu — —
linux-azure-5.4 affected Ubuntu:18.04:LTS linux-azure-5.4 —
linux-azure-fde affected Ubuntu:20.04:LTS linux-azure-fde —
linux-gcp affected Ubuntu:20.04:LTS linux-gcp —
linux-gcp-5.4 affected Ubuntu:18.04:LTS linux-gcp-5.4 —
linux-gke affected Ubuntu:20.04:LTS linux-gke —
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop —
linux-gkeop-5.4 affected Ubuntu:18.04:LTS linux-gkeop-5.4 —
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4 —
linux-ibm affected Ubuntu:20.04:LTS linux-ibm —
linux-ibm-5.4 affected Ubuntu:18.04:LTS linux-ibm-5.4 —
linux-kvm affected Ubuntu:20.04:LTS linux-kvm —
linux-oracle affected Ubuntu:20.04:LTS linux-oracle —
linux-oracle-5.4 affected Ubuntu:18.04:LTS linux-oracle-5.4 —
linux-raspi affected Ubuntu:20.04:LTS linux-raspi —
linux-raspi-5.4 affected Ubuntu:18.04:LTS linux-raspi-5.4 —
Upstream advisory

USN-5342-3

USNPoC exploitCRITICAL2022-05-23

python3.7 vulnerability

CVEs:CVE-2021-3426

Affected products

ProductStatusVendorPackageEcosystem
python3.7 affected Ubuntu:Pro:18.04:LTS python3.7 —
Upstream advisory

USN-5444-1

USNPoC exploitHIGH2022-05-24

linux-oem-5.14, linux-oem-5.17 vulnerability

CVEs:CVE-2022-29581

Affected products

ProductStatusVendorPackageEcosystem
linux-oem-5.14 affected Ubuntu:20.04:LTS linux-oem-5.14 —
linux-oem-5.17 affected Ubuntu:22.04:LTS linux-oem-5.17 —
Upstream advisory

USN-5452-1

USNPoC exploitHIGH2022-05-30

ntfs-3g vulnerability

CVEs:CVE-2021-46790

Affected products

ProductStatusVendorPackageEcosystem
ntfs-3g affected Ubuntu:Pro:16.04:LTS ntfs-3g —
ntfs-3g affected Ubuntu:Pro:14.04:LTS ntfs-3g —
Upstream advisory

UBUNTU-CVE-2021-33135

USNPoC exploitMEDIUM2022-05-10

CVEs:CVE-2021-33135

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-5.0 affected Ubuntu:18.04:LTS linux-aws-5.0 —
linux-aws-5.11 affected Ubuntu:20.04:LTS linux-aws-5.11 —
linux-aws-5.13 affected Ubuntu:20.04:LTS linux-aws-5.13 —
linux-aws-5.3 affected Ubuntu:18.04:LTS linux-aws-5.3 —
linux-aws-5.8 affected Ubuntu:20.04:LTS linux-aws-5.8 —
linux-azure affected Ubuntu:18.04:LTS linux-azure —
linux-azure-5.11 affected Ubuntu:20.04:LTS linux-azure-5.11 —
linux-azure-5.13 affected Ubuntu:20.04:LTS linux-azure-5.13 —
linux-azure-5.3 affected Ubuntu:18.04:LTS linux-azure-5.3 —
linux-azure-5.8 affected Ubuntu:20.04:LTS linux-azure-5.8 —
linux-azure-edge affected Ubuntu:18.04:LTS linux-azure-edge —
linux-gcp affected Ubuntu:18.04:LTS linux-gcp —
linux-gcp-5.11 affected Ubuntu:20.04:LTS linux-gcp-5.11 —
linux-gcp-5.13 affected Ubuntu:20.04:LTS linux-gcp-5.13 —
linux-gcp-5.3 affected Ubuntu:18.04:LTS linux-gcp-5.3 —
linux-gcp-5.8 affected Ubuntu:20.04:LTS linux-gcp-5.8 —
linux-gke-4.15 affected Ubuntu:18.04:LTS linux-gke-4.15 —
linux-hwe affected Ubuntu:18.04:LTS linux-hwe —
linux-hwe-5.11 affected Ubuntu:20.04:LTS linux-hwe-5.11 —
linux-hwe-5.13 affected Ubuntu:20.04:LTS linux-hwe-5.13 —
linux-hwe-5.8 affected Ubuntu:20.04:LTS linux-hwe-5.8 —
linux-hwe-edge affected Ubuntu:16.04:LTS linux-hwe-edge —
linux-intel-5.13 affected Ubuntu:20.04:LTS linux-intel-5.13 —
linux-intel-iotg-5.15 affected Ubuntu:20.04:LTS linux-intel-iotg-5.15 —
linux-intel-iot-realtime affected Ubuntu:22.04:LTS linux-intel-iot-realtime —
linux-oem affected Ubuntu:18.04:LTS linux-oem —
linux-oem-5.10 affected Ubuntu:20.04:LTS linux-oem-5.10 —
linux-oem-5.13 affected Ubuntu:20.04:LTS linux-oem-5.13 —
linux-oem-5.14 affected Ubuntu:20.04:LTS linux-oem-5.14 —
linux-oem-5.6 affected Ubuntu:20.04:LTS linux-oem-5.6 —
linux-oracle-5.0 affected Ubuntu:18.04:LTS linux-oracle-5.0 —
linux-oracle-5.11 affected Ubuntu:20.04:LTS linux-oracle-5.11 —
linux-oracle-5.13 affected Ubuntu:20.04:LTS linux-oracle-5.13 —
linux-oracle-5.3 affected Ubuntu:18.04:LTS linux-oracle-5.3 —
linux-oracle-5.8 affected Ubuntu:20.04:LTS linux-oracle-5.8 —
linux-raspi2 affected Ubuntu:20.04:LTS linux-raspi2 —
linux-raspi-realtime affected Ubuntu:24.04:LTS linux-raspi-realtime —
linux-realtime affected Ubuntu:22.04:LTS linux-realtime —
linux-realtime affected Ubuntu:Pro:Realtime:22.04:LTS linux-realtime —
linux-riscv affected Ubuntu:20.04:LTS linux-riscv —
linux-riscv-5.11 affected Ubuntu:20.04:LTS linux-riscv-5.11 —
linux-riscv-5.8 affected Ubuntu:20.04:LTS linux-riscv-5.8 —
Upstream advisory

USN-5400-1

USNCoalition ESS 30-63%HIGH2022-05-03

mysql-5.7, mysql-8.0 vulnerabilities

CVEs:CVE-2022-21412CVE-2022-21413CVE-2022-21414CVE-2022-21415CVE-2022-21417CVE-2022-21418CVE-2022-21423CVE-2022-21425CVE-2022-21427CVE-2022-21435CVE-2022-21436CVE-2022-21437CVE-2022-21438CVE-2022-21440CVE-2022-21444CVE-2022-21451CVE-2022-21452CVE-2022-21454CVE-2022-21457CVE-2022-21459CVE-2022-21460CVE-2022-21462CVE-2022-21478

Affected products

ProductStatusVendorPackageEcosystem
mysql-5.7 affected Ubuntu:18.04:LTS mysql-5.7 —
mysql-8.0 affected Ubuntu:22.04:LTS mysql-8.0 —
mysql-8.0 affected Ubuntu:20.04:LTS mysql-8.0 —
Upstream advisory

USN-5429-1

USNCoalition ESS < 30%HIGH2022-05-18

bind9 vulnerability

CVEs:CVE-2022-1183

Affected products

ProductStatusVendorPackageEcosystem
bind9 affected Ubuntu:22.04:LTS bind9 —
Upstream advisory

USN-5410-1

USNCoalition ESS < 30%HIGH2022-05-11

nss vulnerability

CVEs:CVE-2020-25648

Affected products

ProductStatusVendorPackageEcosystem
nss affected Ubuntu:18.04:LTS nss —
nss affected Ubuntu:20.04:LTS nss —
Upstream advisory

USN-5438-2

USNCoalition ESS < 30%HIGH2022-05-24

htmldoc vulnerability

CVEs:CVE-2021-23165

Affected products

ProductStatusVendorPackageEcosystem
htmldoc affected Ubuntu:Pro:14.04:LTS htmldoc —
htmldoc affected Ubuntu:Pro:16.04:LTS htmldoc —
Upstream advisory

USN-5354-2

USNCoalition ESS < 30%HIGH2022-05-05

twisted vulnerability

CVEs:CVE-2022-21716

Affected products

ProductStatusVendorPackageEcosystem
twisted affected Ubuntu:22.04:LTS twisted —
twisted affected Ubuntu:Pro:14.04:LTS twisted —
twisted affected Ubuntu:Pro:16.04:LTS twisted —
Upstream advisory

USN-5453-1

USNCoalition ESS < 30%HIGH2022-05-30

freetype vulnerability

CVEs:CVE-2022-27406

Affected products

ProductStatusVendorPackageEcosystem
freetype affected Ubuntu:Pro:16.04:LTS freetype —
Upstream advisory

USN-5446-2

USNCoalition ESS < 30%HIGH2022-05-30

dpkg vulnerability

CVEs:CVE-2022-1664

Affected products

ProductStatusVendorPackageEcosystem
dpkg affected Ubuntu:Pro:16.04:LTS dpkg —
Upstream advisory

USN-5446-1

USNCoalition ESS < 30%HIGH2022-05-26

dpkg vulnerability

CVEs:CVE-2022-1664

Affected products

ProductStatusVendorPackageEcosystem
dpkg affected Ubuntu:20.04:LTS dpkg —
dpkg affected Ubuntu:22.04:LTS dpkg —
dpkg affected Ubuntu:18.04:LTS dpkg —
Upstream advisory

UBUNTU-CVE-2021-34085

USNCoalition ESS < 30%CRITICAL2022-05-11

CVEs:CVE-2021-34085

Affected products

ProductStatusVendorPackageEcosystem
mp3gain affected Ubuntu:24.04:LTS mp3gain —
mp3gain affected Ubuntu:25.10 mp3gain —
mp3gain affected Ubuntu:22.04:LTS mp3gain —
Upstream advisory

USN-5409-1

USNCoalition ESS < 30%HIGH2022-05-10

libsndfile vulnerability

CVEs:CVE-2021-4156

Affected products

ProductStatusVendorPackageEcosystem
libsndfile affected Ubuntu:Pro:16.04:LTS libsndfile —
Upstream advisory

UBUNTU-CVE-2018-25033

USNCoalition ESS < 30%HIGH2022-05-08

CVEs:CVE-2018-25033

Affected products

ProductStatusVendorPackageEcosystem
admesh affected Ubuntu:25.10 admesh —
admesh affected Ubuntu:22.04:LTS admesh —
admesh affected Ubuntu:20.04:LTS admesh —
admesh affected Ubuntu:24.04:LTS admesh —
admesh affected Ubuntu:18.04:LTS admesh —
admesh affected Ubuntu:16.04:LTS admesh —
Upstream advisory

UBUNTU-CVE-2021-23792

USNCoalition ESS < 30%CRITICAL2022-05-06

CVEs:CVE-2021-23792

Affected products

ProductStatusVendorPackageEcosystem
libtwelvemonkeys-java affected Ubuntu:20.04:LTS libtwelvemonkeys-java —
libtwelvemonkeys-java affected Ubuntu:22.04:LTS libtwelvemonkeys-java —
libtwelvemonkeys-java affected Ubuntu:24.04:LTS libtwelvemonkeys-java —
libtwelvemonkeys-java affected Ubuntu:18.04:LTS libtwelvemonkeys-java —
libtwelvemonkeys-java affected Ubuntu:25.10 libtwelvemonkeys-java —
Upstream advisory

UBUNTU-CVE-2021-27548

USNCoalition ESS < 30%MEDIUM2022-05-18

CVEs:CVE-2021-27548

Affected products

ProductStatusVendorPackageEcosystem
ipe affected Ubuntu:18.04:LTS ipe —
ipe affected Ubuntu:16.04:LTS ipe —
ipe affected Ubuntu:25.10 ipe —
ipe affected Ubuntu:24.04:LTS ipe —
ipe affected Ubuntu:22.04:LTS ipe —
ipe affected Ubuntu:20.04:LTS ipe —
texlive-bin affected Ubuntu:Pro:16.04:LTS texlive-bin —
texlive-bin affected Ubuntu:25.10 texlive-bin —
texlive-bin affected Ubuntu:Pro:18.04:LTS texlive-bin —
texlive-bin affected Ubuntu:22.04:LTS texlive-bin —
texlive-bin affected Ubuntu:Pro:20.04:LTS texlive-bin —
texlive-bin affected Ubuntu:24.04:LTS texlive-bin —
xpdf affected Ubuntu:22.04:LTS xpdf —
xpdf affected Ubuntu:16.04:LTS xpdf —
xpdf affected Ubuntu:25.10 xpdf —
xpdf affected Ubuntu:18.04:LTS xpdf —
xpdf affected Ubuntu:24.04:LTS xpdf —
Upstream advisory

USN-5259-3

USNCoalition ESS < 30%CRITICAL2022-05-11

cron regression

CVEs:CVE-2017-9525

Affected products

ProductStatusVendorPackageEcosystem
cron affected Ubuntu:18.04:LTS cron —
cron affected Ubuntu:Pro:16.04:LTS cron —
cron affected Ubuntu — —
Upstream advisory

USN-5382-2

USNCoalition ESS < 30%HIGH2022-05-02

libinput vulnerability

CVEs:CVE-2022-1215

Affected products

ProductStatusVendorPackageEcosystem
libinput affected Ubuntu:22.04:LTS libinput —
Upstream advisory

USN-5244-2

USNCoalition ESS < 30%CRITICAL2022-05-09

dbus vulnerability

CVEs:CVE-2020-35512

Affected products

ProductStatusVendorPackageEcosystem
dbus affected Ubuntu:20.04:LTS dbus —
dbus affected Ubuntu:18.04:LTS dbus —
Upstream advisory

USN-5439-1

USNCoalition ESS < 30%MEDIUM2022-05-24

accountsservice vulnerability

CVEs:CVE-2022-1804

Affected products

ProductStatusVendorPackageEcosystem
accountsservice affected Ubuntu:22.04:LTS accountsservice —
Upstream advisory

USN-5449-1

USNEPSS <= 49%CRITICAL2022-05-26

libxv vulnerability

CVEs:CVE-2016-5407

Affected products

ProductStatusVendorPackageEcosystem
libxv affected Ubuntu:Pro:16.04:LTS libxv —
Upstream advisory

USN-5437-1

USNEPSS <= 49%CRITICAL2022-05-23

libxfixes vulnerability

CVEs:CVE-2016-7944

Affected products

ProductStatusVendorPackageEcosystem
libxfixes affected Ubuntu:Pro:16.04:LTS libxfixes —
Upstream advisory

USN-5447-1

USNAll remaining2022-05-26

logrotate vulnerability

Affected products

ProductStatusVendorPackageEcosystem
logrotate affected Ubuntu:22.04:LTS logrotate —
Upstream advisory

USN-5441-1

USNAll remainingHIGH2022-05-24

webkit2gtk vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
webkit2gtk affected Ubuntu:20.04:LTS webkit2gtk —
webkit2gtk affected Ubuntu:22.04:LTS webkit2gtk —
Upstream advisory

USN-5438-1

USNAll remaining2022-05-23

htmldoc vulnerability

Affected products

ProductStatusVendorPackageEcosystem
htmldoc affected Ubuntu:20.04:LTS htmldoc —
htmldoc affected Ubuntu:18.04:LTS htmldoc —
Upstream advisory

USN-5311-2

USNAll remaining2022-05-16

containerd regression

Affected products

ProductStatusVendorPackageEcosystem
containerd affected Ubuntu:20.04:LTS containerd —
Upstream advisory

USN-5400-3

USNAll remainingHIGH2022-05-05

mysql-8.0 regression

Affected products

ProductStatusVendorPackageEcosystem
mysql-8.0 affected Ubuntu:22.04:LTS mysql-8.0 —
mysql-8.0 affected Ubuntu:20.04:LTS mysql-8.0 —
Upstream advisory

USN-5395-2

USNAll remaining2022-05-04

networkd-dispatcher regression

Affected products

ProductStatusVendorPackageEcosystem
networkd-dispatcher affected Ubuntu:20.04:LTS networkd-dispatcher —
networkd-dispatcher affected Ubuntu:18.04:LTS networkd-dispatcher —
networkd-dispatcher affected Ubuntu:22.04:LTS networkd-dispatcher —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.