Canonical Security Advisories · March 2023 — Canonical Security Advisories
108 advisories 279 CVEs 20 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2023-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 20 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-5956-1

USNExploitedCISA KEV listedCRITICAL2023-03-15

libphp-phpmailer vulnerabilities

CVEs:CVE-2016-10033CVE-2016-10045CVE-2017-5223CVE-2017-11503CVE-2018-19296CVE-2020-13625CVE-2021-3603

Affected products

ProductStatusVendorPackageEcosystem
libphp-phpmailer affected Ubuntu:Pro:20.04:LTS libphp-phpmailer
libphp-phpmailer affected Ubuntu:Pro:16.04:LTS libphp-phpmailer
libphp-phpmailer affected Ubuntu:Pro:18.04:LTS libphp-phpmailer
libphp-phpmailer affected Ubuntu:Pro:22.04:LTS libphp-phpmailer
Upstream advisory

USN-5946-1

USNExploitedCISA KEV listedHIGH2023-03-13

libxstream-java vulnerabilities

CVEs:CVE-2021-39139CVE-2021-39140CVE-2021-39141CVE-2021-39144CVE-2021-39145CVE-2021-39146CVE-2021-39147CVE-2021-39148CVE-2021-39149CVE-2021-39150CVE-2021-39151CVE-2021-39152CVE-2021-39153CVE-2021-39154CVE-2022-41966

Affected products

ProductStatusVendorPackageEcosystem
libxstream-java affected Ubuntu:18.04:LTS libxstream-java
libxstream-java affected Ubuntu:Pro:14.04:LTS libxstream-java
libxstream-java affected Ubuntu:22.04:LTS libxstream-java
libxstream-java affected Ubuntu:Pro:16.04:LTS libxstream-java
libxstream-java affected Ubuntu:20.04:LTS libxstream-java
Upstream advisory

USN-5987-1

USNExploitedCISA KEV listedHIGH2023-03-29

linux-gke, linux-gke-5.15, linux-ibm, linux-kvm vulnerabilities

CVEs:CVE-2022-2196CVE-2022-3424CVE-2022-4382CVE-2022-36280CVE-2022-41218CVE-2022-48423CVE-2022-48424CVE-2023-0045CVE-2023-0210CVE-2023-0266CVE-2023-23454CVE-2023-23455CVE-2023-23559CVE-2023-26606CVE-2023-28328

Affected products

ProductStatusVendorPackageEcosystem
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gke-5.15 affected Ubuntu:20.04:LTS linux-gke-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
Upstream advisory

USN-5982-1

USNExploitedCISA KEV listedHIGH2023-03-28

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-gcp, linux-gcp-5.15, linux-gkeop, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities

CVEs:CVE-2022-2196CVE-2022-3424CVE-2022-4382CVE-2022-36280CVE-2022-41218CVE-2022-48423CVE-2022-48424CVE-2023-0045CVE-2023-0210CVE-2023-0266CVE-2023-23454CVE-2023-23455CVE-2023-23559CVE-2023-26606CVE-2023-28328

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-azure-fde affected Ubuntu:22.04:LTS linux-azure-fde
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-5975-1

USNExploitedCISA KEV listedHIGH2023-03-27

linux-azure vulnerabilities

CVEs:CVE-2021-3669CVE-2022-2663CVE-2022-3424CVE-2022-3521CVE-2022-3545CVE-2022-3628CVE-2022-3640CVE-2022-3646CVE-2022-3649CVE-2022-20369CVE-2022-26373CVE-2022-29900CVE-2022-29901CVE-2022-36280CVE-2022-39842CVE-2022-41218CVE-2022-41849CVE-2022-41850CVE-2022-42328CVE-2022-42329CVE-2022-42895CVE-2022-43750CVE-2022-47929CVE-2023-0045CVE-2023-0266CVE-2023-0394CVE-2023-0461CVE-2023-23455CVE-2023-23559CVE-2023-26607CVE-2023-28328

Affected products

ProductStatusVendorPackageEcosystem
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
Upstream advisory

USN-5924-1

USNExploitedCISA KEV listedHIGH2023-03-06

linux-azure, linux-azure, linux-azure vulnerabilities

CVEs:CVE-2021-3669CVE-2022-2663CVE-2022-3424CVE-2022-3521CVE-2022-3545CVE-2022-3628CVE-2022-3640CVE-2022-3646CVE-2022-3649CVE-2022-20369CVE-2022-26373CVE-2022-29900CVE-2022-29901CVE-2022-36280CVE-2022-39842CVE-2022-41218CVE-2022-41849CVE-2022-41850CVE-2022-42328CVE-2022-42329CVE-2022-42895CVE-2022-43750CVE-2022-47929CVE-2023-0045CVE-2023-0266CVE-2023-0394CVE-2023-0461CVE-2023-23455CVE-2023-23559

Affected products

ProductStatusVendorPackageEcosystem
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure
Upstream advisory

USN-5951-1

USNExploitedCISA KEV listedHIGH2023-03-14

linux-ibm, linux-ibm-5.4 vulnerabilities

CVEs:CVE-2022-3169CVE-2022-3424CVE-2022-3435CVE-2022-3521CVE-2022-3545CVE-2022-3623CVE-2022-4139CVE-2022-36280CVE-2022-41218CVE-2022-42328CVE-2022-42329CVE-2022-47520CVE-2022-47929CVE-2023-0045CVE-2023-0266CVE-2023-0394CVE-2023-0461CVE-2023-20938CVE-2023-23454CVE-2023-23455

Affected products

ProductStatusVendorPackageEcosystem
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:18.04:LTS linux-ibm-5.4
Upstream advisory

USN-5917-1

USNExploitedCISA KEV listedHIGH2023-03-03

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4 vulnerabilities

CVEs:CVE-2022-3169CVE-2022-3424CVE-2022-3435CVE-2022-3521CVE-2022-3545CVE-2022-3623CVE-2022-4139CVE-2022-36280CVE-2022-41218CVE-2022-42328CVE-2022-42329CVE-2022-47520CVE-2022-47929CVE-2023-0045CVE-2023-0266CVE-2023-0394CVE-2023-0461CVE-2023-20938CVE-2023-23454CVE-2023-23455

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:18.04:LTS linux-azure-5.4
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.4 affected Ubuntu:18.04:LTS linux-oracle-5.4
Upstream advisory

USN-5984-1

USNExploitedCISA KEV listedHIGH2023-03-29

linux, linux-aws, linux-dell300x, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities

CVEs:CVE-2021-3669CVE-2022-3424CVE-2022-36280CVE-2022-41218CVE-2022-47929CVE-2023-0045CVE-2023-0266CVE-2023-0394CVE-2023-23455CVE-2023-23559CVE-2023-28328

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:18.04:LTS linux
linux-aws affected Ubuntu:18.04:LTS linux-aws
linux-dell300x affected Ubuntu:18.04:LTS linux-dell300x
linux-kvm affected Ubuntu:18.04:LTS linux-kvm
linux-oracle affected Ubuntu:18.04:LTS linux-oracle
linux-raspi2 affected Ubuntu:18.04:LTS linux-raspi2
Upstream advisory

USN-5981-1

USNExploitedCISA KEV listedHIGH2023-03-28

linux-aws-hwe, linux-hwe, linux-oracle vulnerabilities

CVEs:CVE-2021-3669CVE-2022-3424CVE-2022-36280CVE-2022-41218CVE-2022-47929CVE-2023-0045CVE-2023-0266CVE-2023-0394CVE-2023-23455CVE-2023-23559CVE-2023-28328

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-oracle affected Ubuntu:Pro:16.04:LTS linux-oracle
Upstream advisory

USN-5942-2

USNExploitedVulnCheck KEV listedNONE2023-03-22

apache2 vulnerability

CVEs:CVE-2023-25690

Affected products

ProductStatusVendorPackageEcosystem
apache2 affected Ubuntu:Pro:16.04:LTS apache2
Upstream advisory

USN-5942-1

USNExploitedVulnCheck KEV listedNONE2023-03-09

apache2 vulnerabilities

CVEs:CVE-2023-25690CVE-2023-27522

Affected products

ProductStatusVendorPackageEcosystem
apache2 affected Ubuntu:18.04:LTS apache2
apache2 affected Ubuntu:20.04:LTS apache2
apache2 affected Ubuntu:22.04:LTS apache2
Upstream advisory

USN-5983-1

USNExploitedVulnCheck KEV listedCRITICAL2023-03-29

php-nette vulnerability

CVEs:CVE-2020-15227

Affected products

ProductStatusVendorPackageEcosystem
php-nette affected Ubuntu:Pro:16.04:LTS php-nette
php-nette affected Ubuntu:18.04:LTS php-nette
Upstream advisory

USN-5855-2

USNWeaponized exploitMEDIUM2023-03-15

imagemagick vulnerabilities

CVEs:CVE-2022-44267CVE-2022-44268

Affected products

ProductStatusVendorPackageEcosystem
imagemagick affected Ubuntu:22.04:LTS imagemagick
imagemagick affected Ubuntu:20.04:LTS imagemagick
Upstream advisory

USN-5990-1

USNActive exploitation (sightings)CRITICAL2023-03-31

musl vulnerabilities

CVEs:CVE-2019-14697CVE-2020-28928

Affected products

ProductStatusVendorPackageEcosystem
musl affected Ubuntu:Pro:18.04:LTS musl
musl affected Ubuntu:Pro:14.04:LTS musl
musl affected Ubuntu:Pro:20.04:LTS musl
musl affected Ubuntu:Pro:16.04:LTS musl
Upstream advisory

USN-5989-1

USNActive exploitation (sightings)HIGH2023-03-30

glusterfs vulnerability

CVEs:CVE-2023-26253

Affected products

ProductStatusVendorPackageEcosystem
glusterfs affected Ubuntu:Pro:16.04:LTS glusterfs
Upstream advisory

USN-5969-1

USNActive exploitation (sightings)HIGH2023-03-23

gif2apng vulnerabilities

CVEs:CVE-2021-45909CVE-2021-45910CVE-2021-45911

Affected products

ProductStatusVendorPackageEcosystem
gif2apng affected Ubuntu:Pro:16.04:LTS gif2apng
gif2apng affected Ubuntu:18.04:LTS gif2apng
gif2apng affected Ubuntu:20.04:LTS gif2apng
Upstream advisory

USN-5937-1

USNActive exploitation (sightings)2023-03-08

opusfile vulnerability

CVEs:CVE-2022-47021

Affected products

ProductStatusVendorPackageEcosystem
opusfile affected Ubuntu:Pro:16.04:LTS opusfile
opusfile affected Ubuntu:Pro:20.04:LTS opusfile
opusfile affected Ubuntu:Pro:18.04:LTS opusfile
opusfile affected Ubuntu:Pro:22.04:LTS opusfile
Upstream advisory

LSN-0092-1

USNPoC exploit2023-03-07

Kernel Live Patch Security Notice

CVEs:CVE-2022-4378CVE-2022-42896CVE-2022-43945

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:22.04:LTS linux
linux affected Ubuntu:Pro:20.04:LTS linux
linux affected Ubuntu:Pro:16.04:LTS linux
linux affected Ubuntu:Pro:18.04:LTS linux
linux-aws affected Ubuntu:Pro:20.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:16.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:22.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:18.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:Pro:20.04:LTS linux-aws-5.15
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-azure affected Ubuntu:Pro:20.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:22.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
linux-azure-4.15 affected Ubuntu:Pro:18.04:LTS linux-azure-4.15
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-gcp affected Ubuntu:Pro:22.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:20.04:LTS linux-gcp
linux-gcp-4.15 affected Ubuntu:Pro:18.04:LTS linux-gcp-4.15
linux-gcp-5.15 affected Ubuntu:Pro:20.04:LTS linux-gcp-5.15
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gke affected Ubuntu:Pro:20.04:LTS linux-gke
linux-gke affected Ubuntu:Pro:22.04:LTS linux-gke
linux-gke-4.15 affected Ubuntu:Pro:18.04:LTS linux-gke-4.15
linux-gke-5.15 affected Ubuntu:Pro:20.04:LTS linux-gke-5.15
linux-gke-5.4 affected Ubuntu:Pro:18.04:LTS linux-gke-5.4
linux-gkeop affected Ubuntu:Pro:20.04:LTS linux-gkeop
linux-gkeop-5.4 affected Ubuntu:Pro:18.04:LTS linux-gkeop-5.4
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:Pro:20.04:LTS linux-ibm
linux-ibm affected Ubuntu:Pro:22.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-lowlatency affected Ubuntu:Pro:22.04:LTS linux-lowlatency
linux-oem affected Ubuntu:Pro:18.04:LTS linux-oem
Upstream advisory

USN-5960-1

USNPoC exploit2023-03-16

python2.7, python3.10, python3.5, python3.6, python3.8 vulnerability

CVEs:CVE-2023-24329

Affected products

ProductStatusVendorPackageEcosystem
python2.7 affected Ubuntu:Pro:14.04:LTS python2.7
python2.7 affected Ubuntu:18.04:LTS python2.7
python2.7 affected Ubuntu:Pro:16.04:LTS python2.7
python3.10 affected Ubuntu:22.04:LTS python3.10
python3.5 affected Ubuntu:Pro:16.04:LTS python3.5
python3.6 affected Ubuntu:18.04:LTS python3.6
python3.8 affected Ubuntu:20.04:LTS python3.8
Upstream advisory

USN-5947-1

USNPoC exploitCRITICAL2023-03-13

php-twig, twig vulnerabilities

CVEs:CVE-2019-9942CVE-2022-23614CVE-2022-39261

Affected products

ProductStatusVendorPackageEcosystem
php-twig affected Ubuntu:Pro:22.04:LTS php-twig
php-twig affected Ubuntu:Pro:20.04:LTS php-twig
twig affected Ubuntu:Pro:16.04:LTS twig
twig affected Ubuntu:Pro:18.04:LTS twig
Upstream advisory

USN-5935-1

USNPoC exploitHIGH2023-03-07

linux-ibm, linux-raspi vulnerabilities

CVEs:CVE-2022-3169CVE-2022-3344CVE-2022-3435CVE-2022-3521CVE-2022-3545CVE-2022-4139CVE-2022-4379CVE-2022-42328CVE-2022-42329CVE-2022-45869CVE-2022-47518CVE-2022-47519CVE-2022-47520CVE-2022-47521CVE-2023-0179CVE-2023-0461CVE-2023-0468CVE-2023-26605

Affected products

ProductStatusVendorPackageEcosystem
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-5912-1

USNPoC exploitHIGH2023-03-02

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15 vulnerabilities

CVEs:CVE-2022-3169CVE-2022-3344CVE-2022-3435CVE-2022-3521CVE-2022-3545CVE-2022-4139CVE-2022-4379CVE-2022-42328CVE-2022-42329CVE-2022-45869CVE-2022-47518CVE-2022-47519CVE-2022-47520CVE-2022-47521CVE-2023-0179CVE-2023-0461CVE-2023-0468CVE-2023-26605

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-aws-5.15 affected Ubuntu
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-azure-fde affected Ubuntu:22.04:LTS linux-azure-fde
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gke-5.15 affected Ubuntu:20.04:LTS linux-gke-5.15
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
Upstream advisory

USN-5931-1

USNPoC exploitHIGH2023-03-07

python3.8 vulnerability

CVEs:CVE-2022-37454

Affected products

ProductStatusVendorPackageEcosystem
python3.8 affected Ubuntu:Pro:18.04:LTS python3.8
Upstream advisory

USN-5930-1

USNPoC exploitHIGH2023-03-07

python3.7 vulnerability

CVEs:CVE-2022-37454

Affected products

ProductStatusVendorPackageEcosystem
python3.7 affected Ubuntu:Pro:18.04:LTS python3.7
Upstream advisory

USN-5767-3

USNPoC exploitCRITICAL2023-03-06

python3.6 vulnerability

CVEs:CVE-2022-37454

Affected products

ProductStatusVendorPackageEcosystem
python3.6 affected Ubuntu:18.04:LTS python3.6
Upstream advisory

USN-5968-1

USNPoC exploitCRITICAL2023-03-22

python-git vulnerability

CVEs:CVE-2022-24439

Affected products

ProductStatusVendorPackageEcosystem
python-git affected Ubuntu:Pro:22.04:LTS python-git
python-git affected Ubuntu:Pro:20.04:LTS python-git
python-git affected Ubuntu:Pro:16.04:LTS python-git
python-git affected Ubuntu:Pro:14.04:LTS python-git
python-git affected Ubuntu:Pro:18.04:LTS python-git
Upstream advisory

USN-5944-1

USNPoC exploitMEDIUM2023-03-10

snakeyaml vulnerabilities

CVEs:CVE-2022-25857CVE-2022-38749CVE-2022-38750CVE-2022-38751

Affected products

ProductStatusVendorPackageEcosystem
snakeyaml affected Ubuntu:Pro:16.04:LTS snakeyaml
snakeyaml affected Ubuntu:20.04:LTS snakeyaml
snakeyaml affected Ubuntu:Pro:14.04:LTS snakeyaml
snakeyaml affected Ubuntu:22.04:LTS snakeyaml
snakeyaml affected Ubuntu:18.04:LTS snakeyaml
Upstream advisory

USN-5945-1

USNPoC exploitHIGH2023-03-13

protobuf vulnerabilities

CVEs:CVE-2021-22569CVE-2021-22570CVE-2022-1941

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Ubuntu:22.04:LTS protobuf
protobuf affected Ubuntu:18.04:LTS protobuf
protobuf affected Ubuntu:Pro:14.04:LTS protobuf
protobuf affected Ubuntu:20.04:LTS protobuf
Upstream advisory

USN-5956-2

USNPoC exploitCRITICAL2023-03-15

libphp-phpmailer vulnerability

CVEs:CVE-2017-11503

Affected products

ProductStatusVendorPackageEcosystem
libphp-phpmailer affected Ubuntu:Pro:16.04:LTS libphp-phpmailer
libphp-phpmailer affected Ubuntu:Pro:18.04:LTS libphp-phpmailer
Upstream advisory

LSN-0093-1

USNPoC exploit2023-03-27

Kernel Live Patch Security Notice

CVEs:CVE-2023-0179CVE-2023-0461

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:22.04:LTS linux
linux affected Ubuntu:Pro:18.04:LTS linux
linux affected Ubuntu:Pro:20.04:LTS linux
linux-aws affected Ubuntu:Pro:18.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:22.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:20.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:Pro:20.04:LTS linux-aws-5.15
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-azure affected Ubuntu:Pro:20.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:22.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
linux-azure-4.15 affected Ubuntu:Pro:18.04:LTS linux-azure-4.15
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-gcp affected Ubuntu:Pro:22.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:20.04:LTS linux-gcp
linux-gcp-4.15 affected Ubuntu:Pro:18.04:LTS linux-gcp-4.15
linux-gcp-5.15 affected Ubuntu:Pro:20.04:LTS linux-gcp-5.15
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gke affected Ubuntu:Pro:20.04:LTS linux-gke
linux-gke affected Ubuntu:Pro:22.04:LTS linux-gke
linux-gke-4.15 affected Ubuntu:Pro:18.04:LTS linux-gke-4.15
linux-gke-5.15 affected Ubuntu:Pro:20.04:LTS linux-gke-5.15
linux-gke-5.4 affected Ubuntu:Pro:18.04:LTS linux-gke-5.4
linux-gkeop affected Ubuntu:Pro:20.04:LTS linux-gkeop
linux-gkeop-5.4 affected Ubuntu:Pro:18.04:LTS linux-gkeop-5.4
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:Pro:20.04:LTS linux-ibm
linux-ibm affected Ubuntu:Pro:22.04:LTS linux-ibm
linux-oem affected Ubuntu:Pro:18.04:LTS linux-oem
Upstream advisory

USN-5910-1

USNPoC exploitCRITICAL2023-03-02

ruby-rack vulnerabilities

CVEs:CVE-2022-44570CVE-2022-44571CVE-2022-44572

Affected products

ProductStatusVendorPackageEcosystem
ruby-rack affected Ubuntu:Pro:22.04:LTS ruby-rack
ruby-rack affected Ubuntu:Pro:18.04:LTS ruby-rack
ruby-rack affected Ubuntu:Pro:14.04:LTS ruby-rack
ruby-rack affected Ubuntu:Pro:16.04:LTS ruby-rack
ruby-rack affected Ubuntu:Pro:20.04:LTS ruby-rack
Upstream advisory

USN-5948-1

USNPoC exploitCRITICAL2023-03-13

python-werkzeug vulnerabilities

CVEs:CVE-2023-23934CVE-2023-25577

Affected products

ProductStatusVendorPackageEcosystem
python-werkzeug affected Ubuntu:20.04:LTS python-werkzeug
python-werkzeug affected Ubuntu:Pro:16.04:LTS python-werkzeug
python-werkzeug affected Ubuntu:22.04:LTS python-werkzeug
python-werkzeug affected Ubuntu:18.04:LTS python-werkzeug
Upstream advisory

USN-5907-1

USNPoC exploitCRITICAL2023-03-02

c-ares vulnerability

CVEs:CVE-2022-4904

Affected products

ProductStatusVendorPackageEcosystem
c-ares affected Ubuntu:22.04:LTS c-ares
c-ares affected Ubuntu:20.04:LTS c-ares
c-ares affected Ubuntu:18.04:LTS c-ares
Upstream advisory

USN-5953-1

USNPoC exploitMEDIUM2023-03-15

ipython vulnerabilities

CVEs:CVE-2015-5607CVE-2022-21699

Affected products

ProductStatusVendorPackageEcosystem
ipython affected Ubuntu:Pro:14.04:LTS ipython
ipython affected Ubuntu:Pro:18.04:LTS ipython
ipython affected Ubuntu:Pro:20.04:LTS ipython
Upstream advisory

USN-5955-1

USNPoC exploitHIGH2023-03-15

emacs24 vulnerability

CVEs:CVE-2022-48339

Affected products

ProductStatusVendorPackageEcosystem
emacs24 affected Ubuntu:Pro:16.04:LTS emacs24
Upstream advisory

USN-5920-1

USNPoC exploitHIGH2023-03-03

linux, linux-aws, linux-dell300x, linux-gcp-4.15, linux-oracle vulnerabilities

CVEs:CVE-2022-3521CVE-2022-3545CVE-2022-3628CVE-2022-3640CVE-2022-4378CVE-2022-42328CVE-2022-42329CVE-2022-42895CVE-2023-0461

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:18.04:LTS linux
linux-aws affected Ubuntu:18.04:LTS linux-aws
linux-dell300x affected Ubuntu:18.04:LTS linux-dell300x
linux-gcp-4.15 affected Ubuntu:18.04:LTS linux-gcp-4.15
linux-oracle affected Ubuntu:18.04:LTS linux-oracle
Upstream advisory

USN-5928-1

USNPoC exploitHIGH2023-03-07

systemd vulnerabilities

CVEs:CVE-2022-3821CVE-2022-4415CVE-2022-45873

Affected products

ProductStatusVendorPackageEcosystem
systemd affected Ubuntu:20.04:LTS systemd
systemd affected Ubuntu:18.04:LTS systemd
systemd affected Ubuntu:Pro:16.04:LTS systemd
systemd affected Ubuntu:22.04:LTS systemd
systemd affected Ubuntu:Pro:14.04:LTS systemd
Upstream advisory

USN-5892-2

USNPoC exploitCRITICAL2023-03-06

nss vulnerability

CVEs:CVE-2023-0767

Affected products

ProductStatusVendorPackageEcosystem
nss affected Ubuntu:Pro:14.04:LTS nss
nss affected Ubuntu:Pro:16.04:LTS nss
Upstream advisory

USN-5906-1

USNPoC exploitMEDIUM2023-03-02

postgresql-12, postgresql-14 vulnerability

CVEs:CVE-2022-41862

Affected products

ProductStatusVendorPackageEcosystem
postgresql-12 affected Ubuntu:20.04:LTS postgresql-12
postgresql-14 affected Ubuntu:22.04:LTS postgresql-14
Upstream advisory

USN-5985-1

USNPoC exploitHIGH2023-03-29

linux-aws-5.4, linux-azure-5.4, linux-gcp-5.4, linux-hwe-5.4, linux-ibm-5.4, linux-oracle-5.4, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2021-3669CVE-2022-2196CVE-2022-4382CVE-2023-23559

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-5.4 affected Ubuntu:18.04:LTS linux-aws-5.4
linux-azure-5.4 affected Ubuntu:18.04:LTS linux-azure-5.4
linux-gcp-5.4 affected Ubuntu:18.04:LTS linux-gcp-5.4
linux-hwe-5.4 affected Ubuntu:18.04:LTS linux-hwe-5.4
linux-ibm-5.4 affected Ubuntu:18.04:LTS linux-ibm-5.4
linux-oracle-5.4 affected Ubuntu:18.04:LTS linux-oracle-5.4
linux-raspi-5.4 affected Ubuntu:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-5980-1

USNPoC exploitHIGH2023-03-28

linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-gkeop, linux-ibm, linux-kvm, linux-oracle, linux-raspi vulnerabilities

CVEs:CVE-2021-3669CVE-2022-2196CVE-2022-4382CVE-2023-23559

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
Upstream advisory

USN-5971-1

USNCoalition ESS < 30%CRITICAL2023-03-24

graphviz vulnerabilities

CVEs:CVE-2018-10196CVE-2019-11023CVE-2020-18032

Affected products

ProductStatusVendorPackageEcosystem
graphviz affected Ubuntu:Pro:20.04:LTS graphviz
graphviz affected Ubuntu:Pro:14.04:LTS graphviz
graphviz affected Ubuntu:Pro:18.04:LTS graphviz
Upstream advisory

USN-5965-1

USNCoalition ESS < 30%HIGH2023-03-21

tigervnc vulnerability

CVEs:CVE-2020-26117

Affected products

ProductStatusVendorPackageEcosystem
tigervnc affected Ubuntu:Pro:20.04:LTS tigervnc
Upstream advisory

USN-5974-1

USNCoalition ESS < 30%HIGH2023-03-27

graphicsmagick vulnerabilities

CVEs:CVE-2018-5685CVE-2018-9018CVE-2018-20184CVE-2018-20189CVE-2019-11006CVE-2020-12672CVE-2022-1270

Affected products

ProductStatusVendorPackageEcosystem
graphicsmagick affected Ubuntu:Pro:16.04:LTS graphicsmagick
graphicsmagick affected Ubuntu:Pro:14.04:LTS graphicsmagick
graphicsmagick affected Ubuntu:Pro:18.04:LTS graphicsmagick
graphicsmagick affected Ubuntu:20.04:LTS graphicsmagick
Upstream advisory

UBUNTU-CVE-2020-27507

USNCoalition ESS < 30%CRITICAL2023-03-15

CVEs:CVE-2020-27507

Affected products

ProductStatusVendorPackageEcosystem
kamailio affected Ubuntu:Pro:20.04:LTS kamailio
kamailio affected Ubuntu:Pro:18.04:LTS kamailio
kamailio affected Ubuntu:Pro:16.04:LTS kamailio
Upstream advisory

USN-5904-2

USNCoalition ESS < 30%MEDIUM2023-03-20

sox regression

CVEs:CVE-2021-33844

Affected products

ProductStatusVendorPackageEcosystem
sox affected Ubuntu:Pro:16.04:LTS sox
sox affected Ubuntu:18.04:LTS sox
sox affected Ubuntu:22.04:LTS sox
sox affected Ubuntu:Pro:14.04:LTS sox
sox affected Ubuntu:20.04:LTS sox
Upstream advisory

USN-5986-1

USNCoalition ESS < 30%CRITICAL2023-03-29

xorg-server, xorg-server-hwe-18.04, xwayland vulnerability

CVEs:CVE-2023-1393

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:20.04:LTS xorg-server
xorg-server affected Ubuntu:18.04:LTS xorg-server
xorg-server affected Ubuntu:22.04:LTS xorg-server
xorg-server-hwe-18.04 affected Ubuntu:18.04:LTS xorg-server-hwe-18.04
xwayland affected Ubuntu:22.04:LTS xwayland
Upstream advisory

UBUNTU-CVE-2020-36691

USNCoalition ESS < 30%MEDIUM2023-03-24

CVEs:CVE-2020-36691

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.0 affected Ubuntu:18.04:LTS linux-aws-5.0
linux-aws-5.11 affected Ubuntu:20.04:LTS linux-aws-5.11
linux-aws-5.13 affected Ubuntu:20.04:LTS linux-aws-5.13
linux-aws-5.3 affected Ubuntu:18.04:LTS linux-aws-5.3
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-aws-5.8 affected Ubuntu:20.04:LTS linux-aws-5.8
linux-aws-fips affected Ubuntu:Pro:FIPS-updates:20.04:LTS linux-aws-fips
linux-aws-fips affected Ubuntu:Pro:FIPS:20.04:LTS linux-aws-fips
linux-azure affected Ubuntu:18.04:LTS linux-azure
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.11 affected Ubuntu:20.04:LTS linux-azure-5.11
linux-azure-5.13 affected Ubuntu:20.04:LTS linux-azure-5.13
linux-azure-5.3 affected Ubuntu:18.04:LTS linux-azure-5.3
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-azure-5.8 affected Ubuntu:20.04:LTS linux-azure-5.8
linux-azure-edge affected Ubuntu:18.04:LTS linux-azure-edge
linux-azure-fde affected Ubuntu:20.04:LTS linux-azure-fde
linux-azure-fips affected Ubuntu:Pro:FIPS-updates:20.04:LTS linux-azure-fips
linux-azure-fips affected Ubuntu:Pro:FIPS:20.04:LTS linux-azure-fips
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-fips affected Ubuntu:Pro:FIPS-updates:20.04:LTS linux-fips
linux-fips affected Ubuntu:Pro:FIPS:20.04:LTS linux-fips
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp affected Ubuntu:18.04:LTS linux-gcp
linux-gcp-5.11 affected Ubuntu:20.04:LTS linux-gcp-5.11
linux-gcp-5.13 affected Ubuntu:20.04:LTS linux-gcp-5.13
linux-gcp-5.3 affected Ubuntu:18.04:LTS linux-gcp-5.3
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gcp-5.8 affected Ubuntu:20.04:LTS linux-gcp-5.8
linux-gcp-fips affected Ubuntu:Pro:FIPS:20.04:LTS linux-gcp-fips
linux-gcp-fips affected Ubuntu:Pro:FIPS-updates:20.04:LTS linux-gcp-fips
linux-gke affected Ubuntu:20.04:LTS linux-gke
linux-gke-4.15 affected Ubuntu:18.04:LTS linux-gke-4.15
linux-gke-5.4 affected Ubuntu:18.04:LTS linux-gke-5.4
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-gkeop-5.4 affected Ubuntu:18.04:LTS linux-gkeop-5.4
linux-hwe affected Ubuntu:18.04:LTS linux-hwe
linux-hwe-5.11 affected Ubuntu:20.04:LTS linux-hwe-5.11
linux-hwe-5.13 affected Ubuntu:20.04:LTS linux-hwe-5.13
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-hwe-5.8 affected Ubuntu:20.04:LTS linux-hwe-5.8
linux-hwe-edge affected Ubuntu:18.04:LTS linux-hwe-edge
linux-hwe-edge affected Ubuntu:16.04:LTS linux-hwe-edge
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-intel-5.13 affected Ubuntu:20.04:LTS linux-intel-5.13
linux-intel-iot-realtime affected Ubuntu:22.04:LTS linux-intel-iot-realtime
linux-iot affected Ubuntu:20.04:LTS linux-iot
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oem affected Ubuntu:18.04:LTS linux-oem
linux-oem-5.10 affected Ubuntu:20.04:LTS linux-oem-5.10
linux-oem-5.13 affected Ubuntu:20.04:LTS linux-oem-5.13
linux-oem-5.14 affected Ubuntu:20.04:LTS linux-oem-5.14
linux-oem-5.6 affected Ubuntu:20.04:LTS linux-oem-5.6
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.0 affected Ubuntu:18.04:LTS linux-oracle-5.0
linux-oracle-5.11 affected Ubuntu:20.04:LTS linux-oracle-5.11
linux-oracle-5.13 affected Ubuntu:20.04:LTS linux-oracle-5.13
linux-oracle-5.3 affected Ubuntu:18.04:LTS linux-oracle-5.3
linux-oracle-5.4 affected Ubuntu:Pro:18.04:LTS linux-oracle-5.4
linux-oracle-5.8 affected Ubuntu:20.04:LTS linux-oracle-5.8
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi2 affected Ubuntu:20.04:LTS linux-raspi2
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4
linux-raspi-realtime affected Ubuntu:24.04:LTS linux-raspi-realtime
linux-realtime affected Ubuntu:22.04:LTS linux-realtime
linux-riscv affected Ubuntu:22.04:LTS linux-riscv
linux-riscv affected Ubuntu:20.04:LTS linux-riscv
linux-riscv-5.11 affected Ubuntu:20.04:LTS linux-riscv-5.11
linux-riscv-5.8 affected Ubuntu:20.04:LTS linux-riscv-5.8
linux-xilinx-zynqmp affected Ubuntu:20.04:LTS linux-xilinx-zynqmp
Upstream advisory

USN-5988-1

USNEPSS <= 49%CRITICAL2023-03-29

xcftools vulnerabilities

CVEs:CVE-2019-5086CVE-2019-5087

Affected products

ProductStatusVendorPackageEcosystem
xcftools affected Ubuntu:Pro:16.04:LTS xcftools
xcftools affected Ubuntu:18.04:LTS xcftools
xcftools affected Ubuntu:20.04:LTS xcftools
Upstream advisory

USN-5855-3

USNAll remainingMEDIUM2023-03-31

imagemagick regression

Affected products

ProductStatusVendorPackageEcosystem
imagemagick affected Ubuntu:22.04:LTS imagemagick
imagemagick affected Ubuntu:20.04:LTS imagemagick
Upstream advisory

USN-5954-2

USNAll remainingHIGH2023-03-27

firefox regressions

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:18.04:LTS firefox
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

USN-5966-2

USNAll remainingHIGH2023-03-23

amanda regression

Affected products

ProductStatusVendorPackageEcosystem
amanda affected Ubuntu:22.04:LTS amanda
amanda affected Ubuntu:20.04:LTS amanda
amanda affected Ubuntu:Pro:14.04:LTS amanda
amanda affected Ubuntu:18.04:LTS amanda
amanda affected Ubuntu:Pro:16.04:LTS amanda
Upstream advisory

USN-5966-1

USNAll remaining2023-03-23

amanda vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
amanda affected Ubuntu:22.04:LTS amanda
amanda affected Ubuntu:16.04:LTS amanda
amanda affected Ubuntu:14.04:LTS amanda
amanda affected Ubuntu:20.04:LTS amanda
amanda affected Ubuntu:18.04:LTS amanda
Upstream advisory

USN-5949-1

USNAll remaining2023-03-13

chromium-browser vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Ubuntu:18.04:LTS chromium-browser
Upstream advisory

USN-5921-1

USNAll remaining2023-03-06

rsync vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
rsync affected Ubuntu:22.04:LTS rsync
rsync affected Ubuntu:20.04:LTS rsync
rsync affected Ubuntu:18.04:LTS rsync
Upstream advisory

USN-5821-4

USNAll remainingHIGH2023-03-02

python-pip regression

Affected products

ProductStatusVendorPackageEcosystem
python-pip affected Ubuntu:Pro:16.04:LTS python-pip
python-pip affected Ubuntu:Pro:14.04:LTS python-pip
python-pip affected Ubuntu:18.04:LTS python-pip
Upstream advisory

USN-5908-1

USNAll remaining2023-03-02

sudo vulnerability

Affected products

ProductStatusVendorPackageEcosystem
sudo affected Ubuntu:22.04:LTS sudo
Upstream advisory

USN-5871-2

USNAll remaining2023-03-02

git regression

Affected products

ProductStatusVendorPackageEcosystem
git affected Ubuntu:18.04:LTS git
Upstream advisory

USN-5880-2

USNAll remainingHIGH2023-03-01

firefox regressions

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:18.04:LTS firefox
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.