Canonical Security Advisories · October 2022 — Canonical Security Advisories
70 advisories 148 CVEs 2 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2022-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-5696-1

USNExploitedVulnCheck KEV listedHIGH2022-10-24

mysql-5.7, mysql-8.0 vulnerabilities

CVEs:CVE-2022-21589CVE-2022-21592CVE-2022-21594CVE-2022-21599CVE-2022-21604CVE-2022-21608CVE-2022-21611CVE-2022-21617CVE-2022-21625CVE-2022-21632CVE-2022-21633CVE-2022-21637CVE-2022-21640CVE-2022-39400CVE-2022-39408CVE-2022-39410

Affected products

ProductStatusVendorPackageEcosystem
mysql-5.7 affected Ubuntu:18.04:LTS mysql-5.7
mysql-8.0 affected Ubuntu:20.04:LTS mysql-8.0
mysql-8.0 affected Ubuntu:22.04:LTS mysql-8.0
Upstream advisory

USN-5690-1

USNWeaponized exploitHIGH2022-10-19

libxdmcp vulnerability

CVEs:CVE-2017-2625

Affected products

ProductStatusVendorPackageEcosystem
libxdmcp affected Ubuntu:Pro:16.04:LTS libxdmcp
libxdmcp affected Ubuntu:Pro:14.04:LTS libxdmcp
Upstream advisory

USN-5257-2

USNActive exploitation (sightings)HIGH2022-10-04

ldns vulnerabilities

CVEs:CVE-2020-19860CVE-2020-19861

Affected products

ProductStatusVendorPackageEcosystem
ldns affected Ubuntu:Pro:20.04:LTS ldns
ldns affected Ubuntu:Pro:22.04:LTS ldns
Upstream advisory

USN-5697-1

USNActive exploitation (sightings)NONE2022-10-25

barbican vulnerability

CVEs:CVE-2022-3100

Affected products

ProductStatusVendorPackageEcosystem
barbican affected Ubuntu:22.04:LTS barbican
barbican affected Ubuntu:18.04:LTS barbican
barbican affected Ubuntu:20.04:LTS barbican
Upstream advisory

USN-5614-2

USNActive exploitation (sightings)CRITICAL2022-10-03

wayland vulnerability

CVEs:CVE-2021-3782

Affected products

ProductStatusVendorPackageEcosystem
wayland affected Ubuntu:Pro:16.04:LTS wayland
Upstream advisory

USN-5570-2

USNPoC exploitCRITICAL2022-10-17

zlib vulnerability

CVEs:CVE-2022-37434

Affected products

ProductStatusVendorPackageEcosystem
zlib affected Ubuntu:22.04:LTS zlib
zlib affected Ubuntu:20.04:LTS zlib
Upstream advisory

USN-5676-1

USNPoC exploitHIGH2022-10-13

postgresql-9.5 vulnerability

CVEs:CVE-2022-1552

Affected products

ProductStatusVendorPackageEcosystem
postgresql-9.5 affected Ubuntu:Pro:16.04:LTS postgresql-9.5
Upstream advisory

USN-5652-1

USNPoC exploitHIGH2022-10-03

linux-azure vulnerabilities

CVEs:CVE-2021-33655CVE-2022-36946

Affected products

ProductStatusVendorPackageEcosystem
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure
Upstream advisory

USN-5702-2

USNPoC exploitHIGH2022-10-26

curl vulnerability

CVEs:CVE-2022-32221

Affected products

ProductStatusVendorPackageEcosystem
curl affected Ubuntu:Pro:14.04:LTS curl
curl affected Ubuntu:Pro:16.04:LTS curl
Upstream advisory

USN-5692-1

USNPoC exploitHIGH2022-10-19

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oem-5.14, linux-oracle, linux-raspi vulnerabilities

CVEs:CVE-2022-2602CVE-2022-41674CVE-2022-42719CVE-2022-42720CVE-2022-42721CVE-2022-42722

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gke-5.15 affected Ubuntu:20.04:LTS linux-gke-5.15
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-oem-5.14 affected Ubuntu:20.04:LTS linux-oem-5.14
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-5691-1

USNPoC exploitHIGH2022-10-19

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gke, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2022-2602CVE-2022-41674CVE-2022-42720CVE-2022-42721

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:18.04:LTS linux-azure-5.4
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp-5.4 affected Ubuntu:18.04:LTS linux-gcp-5.4
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:18.04:LTS linux-ibm-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.4 affected Ubuntu:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi-5.4 affected Ubuntu:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-5669-1

USNPoC exploitHIGH2022-10-10

linux, linux-dell300x, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities

CVEs:CVE-2022-0812CVE-2022-1012CVE-2022-2318CVE-2022-26365CVE-2022-32296CVE-2022-33740CVE-2022-33741CVE-2022-33742CVE-2022-33744

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:18.04:LTS linux
linux-dell300x affected Ubuntu:18.04:LTS linux-dell300x
linux-kvm affected Ubuntu:18.04:LTS linux-kvm
linux-oracle affected Ubuntu:18.04:LTS linux-oracle
linux-raspi2 affected Ubuntu:18.04:LTS linux-raspi2
linux-snapdragon affected Ubuntu:18.04:LTS linux-snapdragon
Upstream advisory

USN-5672-1

USNPoC exploitHIGH2022-10-12

GMP vulnerability

CVEs:CVE-2021-43618

Affected products

ProductStatusVendorPackageEcosystem
gmp affected Ubuntu:Pro:16.04:LTS gmp
gmp affected Ubuntu:20.04:LTS gmp
gmp affected Ubuntu:18.04:LTS gmp
Upstream advisory

USN-5666-1

USNPoC exploitCRITICAL2022-10-10

openssh vulnerability

CVEs:CVE-2021-41617

Affected products

ProductStatusVendorPackageEcosystem
openssh affected Ubuntu:Pro:16.04:LTS openssh
Upstream advisory

USN-5673-1

USNPoC exploitHIGH2022-10-13

unzip vulnerabilities

CVEs:CVE-2021-4217CVE-2022-0529CVE-2022-0530

Affected products

ProductStatusVendorPackageEcosystem
unzip affected Ubuntu:20.04:LTS unzip
unzip affected Ubuntu:18.04:LTS unzip
unzip affected Ubuntu:22.04:LTS unzip
unzip affected Ubuntu:Pro:16.04:LTS unzip
unzip affected Ubuntu:Pro:14.04:LTS unzip
Upstream advisory

USN-5707-1

USNPoC exploitHIGH2022-10-31

libtasn1-6 vulnerability

CVEs:CVE-2021-46848

Affected products

ProductStatusVendorPackageEcosystem
libtasn1-6 affected Ubuntu:Pro:16.04:LTS libtasn1-6
Upstream advisory

USN-5677-1

USNPoC exploitHIGH2022-10-13

linux-gcp, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2021-4159CVE-2022-2318CVE-2022-3176CVE-2022-20369CVE-2022-26365CVE-2022-26373CVE-2022-33740CVE-2022-33741CVE-2022-33742CVE-2022-33744CVE-2022-36879

Affected products

ProductStatusVendorPackageEcosystem
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-oracle-5.4 affected Ubuntu:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi-5.4 affected Ubuntu:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-5668-1

USNPoC exploitHIGH2022-10-10

linux, linux-aws, linux-bluefield, linux-gke, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle vulnerabilities

CVEs:CVE-2021-4159CVE-2022-2318CVE-2022-3176CVE-2022-20369CVE-2022-26365CVE-2022-26373CVE-2022-33740CVE-2022-33741CVE-2022-33742CVE-2022-33744CVE-2022-36879

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:18.04:LTS linux-ibm-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
Upstream advisory

USN-5667-1

USNPoC exploitHIGH2022-10-10

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-raspi vulnerabilities

CVEs:CVE-2022-1882CVE-2022-3176CVE-2022-26373CVE-2022-36879CVE-2022-39189

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-5701-1

USNCoalition ESS < 30%HIGH2022-10-26

jinja2 vulnerability

CVEs:CVE-2020-28493

Affected products

ProductStatusVendorPackageEcosystem
jinja2 affected Ubuntu:Pro:16.04:LTS jinja2
Upstream advisory

USN-5227-3

USNCoalition ESS < 30%HIGH2022-10-24

pillow vulnerability

CVEs:CVE-2022-22817

Affected products

ProductStatusVendorPackageEcosystem
pillow affected Ubuntu:18.04:LTS pillow
pillow affected Ubuntu:20.04:LTS pillow
Upstream advisory

USN-5205-1

USNCoalition ESS < 30%HIGH2022-10-04

tcpreplay vulnerabilities

CVEs:CVE-2018-13112CVE-2018-17580CVE-2018-17582CVE-2018-17974CVE-2018-18407CVE-2018-18408CVE-2018-20552CVE-2018-20553CVE-2020-12740CVE-2020-24265CVE-2020-24266CVE-2022-27416CVE-2022-28487

Affected products

ProductStatusVendorPackageEcosystem
tcpreplay affected Ubuntu:Pro:22.04:LTS tcpreplay
tcpreplay affected Ubuntu:Pro:16.04:LTS tcpreplay
tcpreplay affected Ubuntu:Pro:20.04:LTS tcpreplay
tcpreplay affected
tcpreplay affected Ubuntu:Pro:18.04:LTS tcpreplay
Upstream advisory

USN-5651-2

USNCoalition ESS < 30%HIGH2022-10-03

strongswan vulnerability

CVEs:CVE-2022-40617

Affected products

ProductStatusVendorPackageEcosystem
strongswan affected Ubuntu:Pro:14.04:LTS strongswan
strongswan affected Ubuntu:Pro:16.04:LTS strongswan
Upstream advisory

USN-5651-1

USNCoalition ESS < 30%HIGH2022-10-03

strongswan vulnerability

CVEs:CVE-2022-40617

Affected products

ProductStatusVendorPackageEcosystem
strongswan affected Ubuntu:20.04:LTS strongswan
strongswan affected Ubuntu:18.04:LTS strongswan
strongswan affected Ubuntu:22.04:LTS strongswan
Upstream advisory

USN-5688-1

USNCoalition ESS < 30%CRITICAL2022-10-19

libksba vulnerability

CVEs:CVE-2022-3515

Affected products

ProductStatusVendorPackageEcosystem
libksba affected Ubuntu:20.04:LTS libksba
libksba affected Ubuntu:18.04:LTS libksba
libksba affected Ubuntu:Pro:16.04:LTS libksba
libksba affected Ubuntu:Pro:14.04:LTS libksba
libksba affected Ubuntu:22.04:LTS libksba
Upstream advisory

USN-5704-1

USNCoalition ESS < 30%MEDIUM2022-10-27

dbus vulnerabilities

CVEs:CVE-2022-42010CVE-2022-42011CVE-2022-42012

Affected products

ProductStatusVendorPackageEcosystem
dbus affected Ubuntu:Pro:14.04:LTS dbus
dbus affected Ubuntu:20.04:LTS dbus
dbus affected Ubuntu:22.04:LTS dbus
dbus affected Ubuntu:18.04:LTS dbus
dbus affected Ubuntu:Pro:16.04:LTS dbus
Upstream advisory

USN-5689-1

USNCoalition ESS < 30%NONE2022-10-19

perl vulnerability

CVEs:CVE-2020-16156

Affected products

ProductStatusVendorPackageEcosystem
perl affected Ubuntu:18.04:LTS perl
perl affected Ubuntu:20.04:LTS perl
perl affected Ubuntu:22.04:LTS perl
perl affected Ubuntu:Pro:14.04:LTS perl
perl affected Ubuntu:Pro:16.04:LTS perl
Upstream advisory

UBUNTU-CVE-2021-20251

USNCoalition ESS < 30%MEDIUM2022-10-19

CVEs:CVE-2021-20251

Affected products

ProductStatusVendorPackageEcosystem
samba affected Ubuntu:Pro:16.04:LTS samba
samba affected Ubuntu:Pro:18.04:LTS samba
samba affected Ubuntu:Pro:14.04:LTS samba
samba affected Ubuntu:Pro:20.04:LTS samba
samba affected Ubuntu:22.04:LTS samba
Upstream advisory

USN-5658-1

USNCoalition ESS < 30%CRITICAL2022-10-05

isc-dhcp vulnerabilities

CVEs:CVE-2022-2928CVE-2022-2929

Affected products

ProductStatusVendorPackageEcosystem
isc-dhcp affected Ubuntu:18.04:LTS isc-dhcp
isc-dhcp affected Ubuntu:22.04:LTS isc-dhcp
isc-dhcp affected Ubuntu:20.04:LTS isc-dhcp
Upstream advisory

USN-5698-2

USNCoalition ESS < 30%CRITICAL2022-10-25

openvswitch vulnerability

CVEs:CVE-2022-32166

Affected products

ProductStatusVendorPackageEcosystem
openvswitch affected Ubuntu:Pro:16.04:LTS openvswitch
Upstream advisory

USN-5657-1

USNEPSS <= 49%HIGH2022-10-05

graphite2 vulnerability

CVEs:CVE-2018-7999

Affected products

ProductStatusVendorPackageEcosystem
graphite2 affected Ubuntu:Pro:16.04:LTS graphite2
Upstream advisory

USN-5671-1

USNEPSS <= 49%MEDIUM2022-10-12

advancecomp vulnerabilities

CVEs:CVE-2019-8379CVE-2019-8383

Affected products

ProductStatusVendorPackageEcosystem
advancecomp affected Ubuntu:Pro:16.04:LTS advancecomp
advancecomp affected Ubuntu:18.04:LTS advancecomp
Upstream advisory

USN-5698-1

USNAll remaining2022-10-25

openvswitch vulnerability

Affected products

ProductStatusVendorPackageEcosystem
openvswitch affected Ubuntu:18.04:LTS openvswitch
Upstream advisory

USN-5686-1

USNAll remaining2022-10-18

git vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
git affected Ubuntu:22.04:LTS git
git affected Ubuntu:20.04:LTS git
git affected Ubuntu:18.04:LTS git
Upstream advisory

USN-5670-1

USNAll remaining2022-10-11

dotnet6 vulnerability

Affected products

ProductStatusVendorPackageEcosystem
dotnet6 affected Ubuntu:22.04:LTS dotnet6
Upstream advisory

USN-5659-1

USNAll remaining2022-10-05

kitty vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
kitty affected Ubuntu:22.04:LTS kitty
kitty affected Ubuntu:20.04:LTS kitty
Upstream advisory

USN-5653-1

USNAll remaining2022-10-04

python-django vulnerability

Affected products

ProductStatusVendorPackageEcosystem
python-django affected Ubuntu:20.04:LTS python-django
python-django affected Ubuntu:22.04:LTS python-django
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.