Canonical Security Advisories · November 2022 — Canonical Security Advisories
63 advisories 199 CVEs

Ubuntu Security Notices (USN-NNNN-N) for 2022-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-5744-1

USNWeaponized exploitHIGH2022-11-28

libice vulnerability

CVEs:CVE-2017-2626

Affected products

ProductStatusVendorPackageEcosystem
libice affected Ubuntu:18.04:LTS libice
libice affected Ubuntu:Pro:16.04:LTS libice
Upstream advisory

USN-5739-1

USNActive exploitation (sightings)HIGH2022-11-23

mariadb-10.3, mariadb-10.6 vulnerabilities

CVEs:CVE-2018-25032CVE-2021-46669CVE-2022-21427CVE-2022-27376CVE-2022-27377CVE-2022-27378CVE-2022-27379CVE-2022-27380CVE-2022-27381CVE-2022-27382CVE-2022-27383CVE-2022-27384CVE-2022-27386CVE-2022-27387CVE-2022-27444CVE-2022-27445CVE-2022-27446CVE-2022-27447CVE-2022-27448CVE-2022-27449CVE-2022-27451CVE-2022-27452CVE-2022-27455CVE-2022-27456CVE-2022-27457CVE-2022-27458CVE-2022-32081CVE-2022-32082CVE-2022-32083CVE-2022-32084CVE-2022-32085CVE-2022-32086CVE-2022-32087CVE-2022-32088CVE-2022-32089CVE-2022-32091

Affected products

ProductStatusVendorPackageEcosystem
mariadb-10.3 affected Ubuntu:20.04:LTS mariadb-10.3
mariadb-10.6 affected Ubuntu:22.04:LTS mariadb-10.6
Upstream advisory

USN-5741-1

USNActive exploitation (sightings)CRITICAL2022-11-24

exim4 vulnerability

CVEs:CVE-2022-3559

Affected products

ProductStatusVendorPackageEcosystem
exim4 affected Ubuntu:20.04:LTS exim4
exim4 affected Ubuntu:22.04:LTS exim4
exim4 affected Ubuntu:18.04:LTS exim4
Upstream advisory

USN-5724-1

USNActive exploitation (sightings)HIGH2022-11-11

thunderbird vulnerabilities

CVEs:CVE-2022-3266CVE-2022-39236CVE-2022-39249CVE-2022-39250CVE-2022-39251CVE-2022-40956CVE-2022-40957CVE-2022-40958CVE-2022-40959CVE-2022-40960CVE-2022-40962CVE-2022-42927CVE-2022-42928CVE-2022-42929CVE-2022-42932

Affected products

ProductStatusVendorPackageEcosystem
thunderbird affected Ubuntu:22.04:LTS thunderbird
thunderbird affected Ubuntu:20.04:LTS thunderbird
thunderbird affected Ubuntu:18.04:LTS thunderbird
Upstream advisory

USN-5735-1

USNActive exploitation (sightings)CRITICAL2022-11-22

sysstat vulnerability

CVEs:CVE-2022-39377

Affected products

ProductStatusVendorPackageEcosystem
sysstat affected Ubuntu:Pro:16.04:LTS sysstat
Upstream advisory

LSN-0090-1

USNCoalition ESS > 63%2022-11-16

Kernel Live Patch Security Notice

CVEs:CVE-2022-1015CVE-2022-2602CVE-2022-41674CVE-2022-42720CVE-2022-42721CVE-2022-42722

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:22.04:LTS linux
linux affected Ubuntu:Pro:20.04:LTS linux
linux-aws affected Ubuntu:Pro:20.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:Pro:20.04:LTS linux-aws-5.15
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:Pro:20.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:22.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-gcp affected Ubuntu:Pro:20.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:Pro:20.04:LTS linux-gcp-5.15
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gke affected Ubuntu:Pro:20.04:LTS linux-gke
linux-gke affected Ubuntu:Pro:22.04:LTS linux-gke
linux-gke-5.15 affected Ubuntu:Pro:20.04:LTS linux-gke-5.15
linux-gke-5.4 affected Ubuntu:Pro:18.04:LTS linux-gke-5.4
linux-gkeop affected Ubuntu:Pro:20.04:LTS linux-gkeop
linux-gkeop-5.4 affected Ubuntu:Pro:18.04:LTS linux-gkeop-5.4
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:Pro:22.04:LTS linux-ibm
linux-ibm affected Ubuntu:Pro:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-lowlatency affected Ubuntu:Pro:22.04:LTS linux-lowlatency
Upstream advisory

USN-5716-2

USNPoC exploitCRITICAL2022-11-21

sqlite3 vulnerability

CVEs:CVE-2022-35737

Affected products

ProductStatusVendorPackageEcosystem
sqlite3 affected Ubuntu:Pro:14.04:LTS sqlite3
Upstream advisory

USN-5716-1

USNPoC exploitCRITICAL2022-11-07

sqlite3 vulnerability

CVEs:CVE-2022-35737

Affected products

ProductStatusVendorPackageEcosystem
sqlite3 affected Ubuntu:22.04:LTS sqlite3
sqlite3 affected Ubuntu:18.04:LTS sqlite3
sqlite3 affected Ubuntu:20.04:LTS sqlite3
Upstream advisory

USN-5712-1

USNPoC exploitCRITICAL2022-11-03

sqlite3 vulnerability

CVEs:CVE-2022-35737

Affected products

ProductStatusVendorPackageEcosystem
sqlite3 affected Ubuntu:Pro:16.04:LTS sqlite3
Upstream advisory

USN-5728-2

USNPoC exploitHIGH2022-11-18

linux-azure-fde, linux-gke, linux-gkeop, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2022-2153CVE-2022-2978CVE-2022-3028CVE-2022-3625CVE-2022-3635CVE-2022-20422CVE-2022-29901CVE-2022-40768CVE-2022-41222CVE-2022-42703CVE-2022-42719

Affected products

ProductStatusVendorPackageEcosystem
linux-azure-fde affected Ubuntu:20.04:LTS linux-azure-fde
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-raspi-5.4 affected Ubuntu:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-5728-1

USNPoC exploitHIGH2022-11-17

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi vulnerabilities

CVEs:CVE-2022-2153CVE-2022-2978CVE-2022-3028CVE-2022-3625CVE-2022-3635CVE-2022-20422CVE-2022-29901CVE-2022-40768CVE-2022-41222CVE-2022-42703CVE-2022-42719

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:18.04:LTS linux-azure-5.4
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:18.04:LTS linux-ibm-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.4 affected Ubuntu:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
Upstream advisory

USN-5742-1

USNPoC exploitMEDIUM2022-11-24

jbigkit vulnerability

CVEs:CVE-2017-9937

Affected products

ProductStatusVendorPackageEcosystem
jbigkit affected Ubuntu:Pro:16.04:LTS jbigkit
jbigkit affected Ubuntu:20.04:LTS jbigkit
jbigkit affected Ubuntu:Pro:14.04:LTS jbigkit
jbigkit affected Ubuntu:22.04:LTS jbigkit
jbigkit affected Ubuntu:18.04:LTS jbigkit
Upstream advisory

USN-5719-1

USNPoC exploitHIGH2022-11-09

openjdk-8, openjdk-lts, openjdk-17, openjdk-19 vulnerabilities

CVEs:CVE-2022-21618CVE-2022-21619CVE-2022-21624CVE-2022-21626CVE-2022-21628CVE-2022-39399

Affected products

ProductStatusVendorPackageEcosystem
openjdk-17 affected Ubuntu:22.04:LTS openjdk-17
openjdk-17 affected Ubuntu:20.04:LTS openjdk-17
openjdk-17 affected Ubuntu:18.04:LTS openjdk-17
openjdk-19 affected Ubuntu:22.04:LTS openjdk-19
openjdk-8 affected Ubuntu:20.04:LTS openjdk-8
openjdk-8 affected Ubuntu:18.04:LTS openjdk-8
openjdk-8 affected Ubuntu:Pro:16.04:LTS openjdk-8
openjdk-8 affected Ubuntu:22.04:LTS openjdk-8
openjdk-lts affected Ubuntu:22.04:LTS openjdk-lts
openjdk-lts affected Ubuntu:20.04:LTS openjdk-lts
openjdk-lts affected Ubuntu:18.04:LTS openjdk-lts
Upstream advisory

USN-5638-3

USNPoC exploitCRITICAL2022-11-23

expat vulnerability

CVEs:CVE-2022-43680

Affected products

ProductStatusVendorPackageEcosystem
expat affected Ubuntu:Pro:16.04:LTS expat
expat affected Ubuntu:20.04:LTS expat
expat affected Ubuntu:22.04:LTS expat
expat affected Ubuntu:18.04:LTS expat
Upstream advisory

USN-5638-2

USNPoC exploitCRITICAL2022-11-17

expat vulnerabilities

CVEs:CVE-2022-40674CVE-2022-43680

Affected products

ProductStatusVendorPackageEcosystem
expat affected Ubuntu:20.04:LTS expat
expat affected Ubuntu:22.04:LTS expat
expat affected Ubuntu:18.04:LTS expat
Upstream advisory

UBUNTU-CVE-2021-33621

USNPoC exploitHIGH2022-11-18

CVEs:CVE-2021-33621

Affected products

ProductStatusVendorPackageEcosystem
jruby affected Ubuntu:18.04:LTS jruby
jruby affected Ubuntu:20.04:LTS jruby
jruby affected Ubuntu:24.04:LTS jruby
jruby affected Ubuntu:16.04:LTS jruby
jruby affected Ubuntu:Pro:14.04:LTS jruby
jruby affected Ubuntu:25.10 jruby
ruby2.3 affected Ubuntu:Pro:16.04:LTS ruby2.3
ruby2.5 affected Ubuntu:18.04:LTS ruby2.5
ruby2.7 affected Ubuntu:20.04:LTS ruby2.7
ruby3.0 affected Ubuntu:22.04:LTS ruby3.0
Upstream advisory

USN-5726-1

USNPoC exploitHIGH2022-11-16

firefox vulnerabilities

CVEs:CVE-2022-40674CVE-2022-45403CVE-2022-45404CVE-2022-45405CVE-2022-45406CVE-2022-45407CVE-2022-45408CVE-2022-45409CVE-2022-45410CVE-2022-45411CVE-2022-45412CVE-2022-45413CVE-2022-45415CVE-2022-45416CVE-2022-45417CVE-2022-45418CVE-2022-45419CVE-2022-45420CVE-2022-45421

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:18.04:LTS firefox
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

USN-5750-1

USNPoC exploitHIGH2022-11-30

gnutls28 vulnerability

CVEs:CVE-2021-4209

Affected products

ProductStatusVendorPackageEcosystem
gnutls28 affected Ubuntu:Pro:16.04:LTS gnutls28
Upstream advisory

USN-5746-1

USNPoC exploitHIGH2022-11-28

harfbuzz vulnerability

CVEs:CVE-2015-9274

Affected products

ProductStatusVendorPackageEcosystem
harfbuzz affected Ubuntu:Pro:16.04:LTS harfbuzz
Upstream advisory

USN-5722-1

USNPoC exploitMEDIUM2022-11-15

nginx vulnerabilities

CVEs:CVE-2022-41741CVE-2022-41742

Affected products

ProductStatusVendorPackageEcosystem
nginx affected Ubuntu:20.04:LTS nginx
nginx affected Ubuntu:Pro:14.04:LTS nginx
nginx affected Ubuntu:22.04:LTS nginx
nginx affected Ubuntu:18.04:LTS nginx
nginx affected Ubuntu:Pro:16.04:LTS nginx
nginx affected Ubuntu
Upstream advisory

USN-5713-1

USNPoC exploitHIGH2022-11-03

python3.10 vulnerability

CVEs:CVE-2022-42919

Affected products

ProductStatusVendorPackageEcosystem
python3.10 affected Ubuntu:22.04:LTS python3.10
Upstream advisory

USN-5727-1

USNPoC exploitHIGH2022-11-16

linux, linux-aws, linux-aws-hwe, linux-dell300x, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities

CVEs:CVE-2022-2153CVE-2022-2978CVE-2022-3028CVE-2022-3635CVE-2022-20422CVE-2022-36879CVE-2022-40768

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:18.04:LTS linux
linux-aws affected Ubuntu:18.04:LTS linux-aws
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-dell300x affected Ubuntu:18.04:LTS linux-dell300x
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-kvm affected Ubuntu:18.04:LTS linux-kvm
linux-oracle affected Ubuntu:18.04:LTS linux-oracle
linux-oracle affected Ubuntu:Pro:16.04:LTS linux-oracle
linux-raspi2 affected Ubuntu:18.04:LTS linux-raspi2
linux-snapdragon affected Ubuntu:18.04:LTS linux-snapdragon
Upstream advisory

USN-5729-2

USNPoC exploitHIGH2022-11-18

linux-gcp-5.15, linux-gke-5.15, linux-intel-iotg, linux-raspi vulnerabilities

CVEs:CVE-2022-2905CVE-2022-2978CVE-2022-3028CVE-2022-3625CVE-2022-3635CVE-2022-20422CVE-2022-39190CVE-2022-40768

Affected products

ProductStatusVendorPackageEcosystem
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gke-5.15 affected Ubuntu:20.04:LTS linux-gke-5.15
linux-intel-iotg affected Ubuntu:22.04:LTS linux-intel-iotg
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-5729-1

USNPoC exploitHIGH2022-11-17

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15 vulnerabilities

CVEs:CVE-2022-2905CVE-2022-2978CVE-2022-3028CVE-2022-3625CVE-2022-3635CVE-2022-20422CVE-2022-39190CVE-2022-40768

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-aws-5.15 affected Ubuntu
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
Upstream advisory

USN-5745-1

USNPoC exploitNONE2022-11-28

shadow vulnerability

CVEs:CVE-2013-4235

Affected products

ProductStatusVendorPackageEcosystem
shadow affected Ubuntu:Pro:14.04:LTS shadow
shadow affected Ubuntu:18.04:LTS shadow
shadow affected Ubuntu:20.04:LTS shadow
shadow affected Ubuntu:22.04:LTS shadow
shadow affected Ubuntu:Pro:16.04:LTS shadow
Upstream advisory

USN-5725-1

USNCoalition ESS < 30%HIGH2022-11-15

golang-1.13 vulnerability

CVEs:CVE-2020-16845

Affected products

ProductStatusVendorPackageEcosystem
golang-1.13 affected Ubuntu:18.04:LTS golang-1.13
golang-1.13 affected Ubuntu:22.04:LTS golang-1.13
golang-1.13 affected Ubuntu:20.04:LTS golang-1.13
Upstream advisory

USN-5733-1

USNCoalition ESS < 30%HIGH2022-11-21

flac vulnerabilities

CVEs:CVE-2017-6888CVE-2020-0499CVE-2021-0561

Affected products

ProductStatusVendorPackageEcosystem
flac affected Ubuntu:22.04:LTS flac
flac affected Ubuntu:20.04:LTS flac
flac affected Ubuntu:Pro:16.04:LTS flac
flac affected Ubuntu:Pro:14.04:LTS flac
flac affected Ubuntu:18.04:LTS flac
Upstream advisory

USN-5736-2

USNCoalition ESS < 30%MEDIUM2022-11-24

imagemagick vulnerabilities

CVEs:CVE-2021-3574CVE-2021-4219CVE-2021-20224CVE-2021-20241CVE-2021-20243CVE-2021-20244CVE-2021-20245CVE-2021-20246CVE-2021-20309CVE-2021-20312CVE-2021-20313CVE-2021-39212CVE-2022-1114CVE-2022-28463CVE-2022-32545CVE-2022-32546CVE-2022-32547

Affected products

ProductStatusVendorPackageEcosystem
imagemagick affected Ubuntu:Pro:22.04:LTS imagemagick
imagemagick affected Ubuntu:Pro:20.04:LTS imagemagick
Upstream advisory

USN-5736-1

USNCoalition ESS < 30%MEDIUM2022-11-24

imagemagick vulnerabilities

CVEs:CVE-2021-3574CVE-2021-4219CVE-2021-20224CVE-2021-20241CVE-2021-20243CVE-2021-20244CVE-2021-20245CVE-2021-20246CVE-2021-20309CVE-2021-20312CVE-2021-20313CVE-2021-39212CVE-2022-1114CVE-2022-28463CVE-2022-32545CVE-2022-32546CVE-2022-32547

Affected products

ProductStatusVendorPackageEcosystem
imagemagick affected Ubuntu:Pro:16.04:LTS imagemagick
imagemagick affected Ubuntu:18.04:LTS imagemagick
imagemagick affected Ubuntu:Pro:14.04:LTS imagemagick
Upstream advisory

USN-5751-1

USNCoalition ESS < 30%HIGH2022-11-30

libmaxminddb vulnerability

CVEs:CVE-2020-28241

Affected products

ProductStatusVendorPackageEcosystem
libmaxminddb affected Ubuntu:Pro:16.04:LTS libmaxminddb
Upstream advisory

USN-5740-1

USNCoalition ESS < 30%CRITICAL2022-11-23

xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04, xwayland vulnerabilities

CVEs:CVE-2022-3550CVE-2022-3551

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:18.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:14.04:LTS xorg-server
xorg-server affected Ubuntu:20.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:16.04:LTS xorg-server
xorg-server affected Ubuntu:22.04:LTS xorg-server
xorg-server-hwe-16.04 affected Ubuntu:Pro:16.04:LTS xorg-server-hwe-16.04
xorg-server-hwe-18.04 affected Ubuntu:18.04:LTS xorg-server-hwe-18.04
xwayland affected Ubuntu:22.04:LTS xwayland
Upstream advisory

USN-5714-1

USNCoalition ESS < 30%HIGH2022-11-08

tiff vulnerabilities

CVEs:CVE-2022-2519CVE-2022-2520CVE-2022-2521CVE-2022-2867CVE-2022-2868CVE-2022-2869CVE-2022-2953CVE-2022-3570CVE-2022-3597CVE-2022-3598CVE-2022-3599CVE-2022-3626CVE-2022-3627CVE-2022-34526

Affected products

ProductStatusVendorPackageEcosystem
tiff affected Ubuntu:18.04:LTS tiff
tiff affected Ubuntu:22.04:LTS tiff
tiff affected Ubuntu:20.04:LTS tiff
tiff affected Ubuntu:Pro:14.04:LTS tiff
tiff affected Ubuntu:Pro:16.04:LTS tiff
Upstream advisory

USN-5718-2

USNCoalition ESS < 30%CRITICAL2022-11-30

pixman vulnerability

CVEs:CVE-2022-44638

Affected products

ProductStatusVendorPackageEcosystem
pixman affected Ubuntu:Pro:16.04:LTS pixman
pixman affected Ubuntu:Pro:14.04:LTS pixman
Upstream advisory

USN-5718-1

USNCoalition ESS < 30%CRITICAL2022-11-08

pixman vulnerability

CVEs:CVE-2022-44638

Affected products

ProductStatusVendorPackageEcosystem
pixman affected Ubuntu:18.04:LTS pixman
pixman affected Ubuntu:20.04:LTS pixman
pixman affected Ubuntu:22.04:LTS pixman
Upstream advisory

USN-5732-1

USNCoalition ESS < 30%CRITICAL2022-11-17

unbound vulnerability

CVEs:CVE-2022-3204

Affected products

ProductStatusVendorPackageEcosystem
unbound affected Ubuntu:20.04:LTS unbound
unbound affected Ubuntu:22.04:LTS unbound
unbound affected Ubuntu:18.04:LTS unbound
Upstream advisory

UBUNTU-CVE-2021-34055

USNCoalition ESS < 30%HIGH2022-11-04

CVEs:CVE-2021-34055

Affected products

ProductStatusVendorPackageEcosystem
jhead affected Ubuntu:18.04:LTS jhead
jhead affected Ubuntu:20.04:LTS jhead
jhead affected Ubuntu:22.04:LTS jhead
jhead affected Ubuntu:Pro:14.04:LTS jhead
jhead affected Ubuntu:Pro:16.04:LTS jhead
Upstream advisory

USN-5721-1

USNCoalition ESS < 30%MEDIUM2022-11-10

wavpack vulnerability

CVEs:CVE-2022-2476

Affected products

ProductStatusVendorPackageEcosystem
wavpack affected Ubuntu:Pro:16.04:LTS wavpack
Upstream advisory

USN-5711-2

USNCoalition ESS < 30%NONE2022-11-03

ntfs-3g vulnerability

CVEs:CVE-2022-40284

Affected products

ProductStatusVendorPackageEcosystem
ntfs-3g affected Ubuntu:Pro:16.04:LTS ntfs-3g
ntfs-3g affected Ubuntu:Pro:14.04:LTS ntfs-3g
Upstream advisory

USN-5711-1

USNCoalition ESS < 30%NONE2022-11-02

ntfs-3g vulnerability

CVEs:CVE-2022-40284

Affected products

ProductStatusVendorPackageEcosystem
ntfs-3g affected Ubuntu:22.04:LTS ntfs-3g
ntfs-3g affected Ubuntu:18.04:LTS ntfs-3g
ntfs-3g affected Ubuntu:20.04:LTS ntfs-3g
Upstream advisory

USN-5749-1

USNEPSS <= 49%MEDIUM2022-11-29

libsamplerate vulnerability

CVEs:CVE-2017-7697

Affected products

ProductStatusVendorPackageEcosystem
libsamplerate affected Ubuntu:Pro:16.04:LTS libsamplerate
Upstream advisory

USN-5737-1

USNEPSS <= 49%MEDIUM2022-11-23

apr-util vulnerability

CVEs:CVE-2017-12618

Affected products

ProductStatusVendorPackageEcosystem
apr-util affected Ubuntu
apr-util affected Ubuntu:Pro:16.04:LTS apr-util
apr-util affected Ubuntu:Pro:14.04:LTS apr-util
Upstream advisory

UBUNTU-CVE-2009-1143

USNEPSS <= 49%HIGH2022-11-23

CVEs:CVE-2009-1143

Affected products

ProductStatusVendorPackageEcosystem
open-vm-tools affected Ubuntu:Pro:20.04:LTS open-vm-tools
open-vm-tools affected Ubuntu:Pro:18.04:LTS open-vm-tools
open-vm-tools affected Ubuntu:Pro:16.04:LTS open-vm-tools
open-vm-tools affected Ubuntu:Pro:14.04:LTS open-vm-tools
Upstream advisory

USN-5745-2

USNAll remainingNONE2022-11-29

shadow regression

Affected products

ProductStatusVendorPackageEcosystem
shadow affected Ubuntu:Pro:14.04:LTS shadow
shadow affected Ubuntu:18.04:LTS shadow
shadow affected Ubuntu:20.04:LTS shadow
shadow affected Ubuntu:Pro:16.04:LTS shadow
Upstream advisory

USN-5748-1

USNAll remaining2022-11-29

sysstat vulnerability

Affected products

ProductStatusVendorPackageEcosystem
sysstat affected Ubuntu:18.04:LTS sysstat
sysstat affected Ubuntu:20.04:LTS sysstat
sysstat affected Ubuntu:22.04:LTS sysstat
Upstream advisory

USN-5731-1

USNAll remaining2022-11-17

multipath-tools vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
multipath-tools affected Ubuntu:22.04:LTS multipath-tools
multipath-tools affected Ubuntu:20.04:LTS multipath-tools
multipath-tools affected Ubuntu:18.04:LTS multipath-tools
Upstream advisory

USN-5709-2

USNAll remainingHIGH2022-11-10

firefox vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:18.04:LTS firefox
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.