Canonical Security Advisories · December 2023 — Canonical Security Advisories
44 advisories 102 CVEs 3 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2023-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-6561-1

USNExploitedVulnCheck KEV listedCRITICAL2023-12-19

libssh vulnerability

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
libssh affected Ubuntu:22.04:LTS libssh —
libssh affected Ubuntu:20.04:LTS libssh —
Upstream advisory

USN-6560-1

USNExploitedVulnCheck KEV listedCRITICAL2023-12-19

openssh vulnerabilities

CVEs:CVE-2023-28531CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
openssh affected Ubuntu:22.04:LTS openssh —
openssh affected Ubuntu:20.04:LTS openssh —
Upstream advisory

USN-6548-2

USNWeaponized exploitHIGH2023-12-12

linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2023-3006CVE-2023-5178CVE-2023-5717CVE-2023-6176CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux-oracle-5.4 affected Ubuntu:Pro:18.04:LTS linux-oracle-5.4 —
linux-raspi affected Ubuntu:20.04:LTS linux-raspi —
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4 —
Upstream advisory

USN-6548-1

USNWeaponized exploitHIGH2023-12-11

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-xilinx-zynqmp vulnerabilities

CVEs:CVE-2023-3006CVE-2023-5178CVE-2023-5717CVE-2023-6176CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux —
linux-aws affected Ubuntu:20.04:LTS linux-aws —
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4 —
linux-azure affected Ubuntu:20.04:LTS linux-azure —
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4 —
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield —
linux-gcp affected Ubuntu:20.04:LTS linux-gcp —
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4 —
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4 —
linux-ibm affected Ubuntu:20.04:LTS linux-ibm —
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4 —
linux-kvm affected Ubuntu:20.04:LTS linux-kvm —
linux-xilinx-zynqmp affected Ubuntu:20.04:LTS linux-xilinx-zynqmp —
Upstream advisory

USN-6557-1

USNWeaponized exploitCRITICAL2023-12-14

vim vulnerabilities

CVEs:CVE-2022-1725CVE-2022-1771CVE-2022-1886CVE-2022-1897CVE-2022-2000CVE-2022-2042CVE-2023-46246CVE-2023-48231CVE-2023-48232CVE-2023-48233CVE-2023-48234CVE-2023-48235CVE-2023-48236CVE-2023-48237CVE-2023-48706

Affected products

ProductStatusVendorPackageEcosystem
vim affected Ubuntu:Pro:18.04:LTS vim —
vim affected Ubuntu:Pro:14.04:LTS vim —
vim affected Ubuntu:20.04:LTS vim —
vim affected Ubuntu:Pro:16.04:LTS vim —
vim affected Ubuntu:22.04:LTS vim —
Upstream advisory

USN-6551-1

USNWeaponized exploitHIGH2023-12-12

ghostscript vulnerability

CVEs:CVE-2023-46751

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Ubuntu:22.04:LTS ghostscript —
Upstream advisory

USN-6500-2

USNActive exploitation (sightings)HIGH2023-12-11

squid3 vulnerabilities

CVEs:CVE-2023-46728CVE-2023-46847

Affected products

ProductStatusVendorPackageEcosystem
squid3 affected Ubuntu:Pro:18.04:LTS squid3 —
squid3 affected Ubuntu:Pro:16.04:LTS squid3 —
Upstream advisory

USN-6555-2

USNActive exploitation (sightings)CRITICAL2023-12-13

xorg-server vulnerabilities

CVEs:CVE-2023-6377CVE-2023-6478

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:Pro:18.04:LTS xorg-server —
xorg-server affected Ubuntu — —
xorg-server affected Ubuntu:Pro:16.04:LTS xorg-server —
Upstream advisory

USN-6555-1

USNActive exploitation (sightings)CRITICAL2023-12-13

xorg-server, xwayland vulnerabilities

CVEs:CVE-2023-6377CVE-2023-6478

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:22.04:LTS xorg-server —
xorg-server affected Ubuntu:20.04:LTS xorg-server —
xwayland affected Ubuntu:22.04:LTS xwayland —
Upstream advisory

USN-6546-2

USNActive exploitation (sightings)HIGH2023-12-14

libreoffice vulnerabilities

CVEs:CVE-2023-6185CVE-2023-6186

Affected products

ProductStatusVendorPackageEcosystem
libreoffice affected Ubuntu:22.04:LTS libreoffice —
libreoffice affected Ubuntu:20.04:LTS libreoffice —
Upstream advisory

USN-6554-1

USNActive exploitation (sightings)NONE2023-12-13

gnome-control-center vulnerability

CVEs:CVE-2023-5616

Affected products

ProductStatusVendorPackageEcosystem
gnome-control-center affected Ubuntu:20.04:LTS gnome-control-center —
gnome-control-center affected Ubuntu:22.04:LTS gnome-control-center —
Upstream advisory

USN-6540-1

USNCoalition ESS > 63%CRITICAL2023-12-07

bluez vulnerability

CVEs:CVE-2023-45866

Affected products

ProductStatusVendorPackageEcosystem
bluez affected Ubuntu:Pro:16.04:LTS bluez —
bluez affected Ubuntu:22.04:LTS bluez —
bluez affected Ubuntu:Pro:18.04:LTS bluez —
bluez affected Ubuntu:20.04:LTS bluez —
Upstream advisory

USN-6534-3

USNPoC exploitHIGH2023-12-13

linux-hwe-6.2, linux-lowlatency-hwe-6.2, linux-nvidia-6.2 vulnerabilities

CVEs:CVE-2023-3773CVE-2023-5158CVE-2023-5178CVE-2023-5717CVE-2023-6039CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-39198CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux-hwe-6.2 affected Ubuntu:22.04:LTS linux-hwe-6.2 —
linux-lowlatency-hwe-6.2 affected Ubuntu:22.04:LTS linux-lowlatency-hwe-6.2 —
linux-nvidia-6.2 affected Ubuntu:22.04:LTS linux-nvidia-6.2 —
Upstream advisory

USN-6549-1

USNPoC exploitHIGH2023-12-11

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gke, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-kvm, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities

CVEs:CVE-2023-3773CVE-2023-5158CVE-2023-5178CVE-2023-5717CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-39198CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux —
linux-aws affected Ubuntu:22.04:LTS linux-aws —
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15 —
linux-azure affected Ubuntu:22.04:LTS linux-azure —
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15 —
linux-azure-fde affected Ubuntu:22.04:LTS linux-azure-fde —
linux-azure-fde-5.15 affected Ubuntu:20.04:LTS linux-azure-fde-5.15 —
linux-gcp affected Ubuntu:22.04:LTS linux-gcp —
linux-gke affected Ubuntu:22.04:LTS linux-gke —
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15 —
linux-ibm affected Ubuntu:22.04:LTS linux-ibm —
linux-ibm-5.15 affected Ubuntu:20.04:LTS linux-ibm-5.15 —
linux-kvm affected Ubuntu:22.04:LTS linux-kvm —
linux-nvidia affected Ubuntu:22.04:LTS linux-nvidia —
linux-oracle affected Ubuntu:22.04:LTS linux-oracle —
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15 —
linux-raspi affected Ubuntu:22.04:LTS linux-raspi —
Upstream advisory

USN-6534-1

USNPoC exploitHIGH2023-12-05

linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-lowlatency, linux-oracle, linux-raspi, linux-starfive vulnerabilities

CVEs:CVE-2023-3773CVE-2023-5158CVE-2023-5178CVE-2023-5717CVE-2023-6039CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-39198CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-6.2 affected Ubuntu:22.04:LTS linux-aws-6.2 —
linux-azure-6.2 affected Ubuntu:22.04:LTS linux-azure-6.2 —
linux-azure-fde-6.2 affected Ubuntu:22.04:LTS linux-azure-fde-6.2 —
Upstream advisory

USN-6550-1

USNPoC exploitCRITICAL2023-12-12

postfixadmin vulnerabilities

CVEs:CVE-2022-29221CVE-2022-31129CVE-2023-28447

Affected products

ProductStatusVendorPackageEcosystem
postfixadmin affected Ubuntu:Pro:20.04:LTS postfixadmin —
postfixadmin affected Ubuntu:Pro:22.04:LTS postfixadmin —
postfixadmin affected Ubuntu:Pro:18.04:LTS postfixadmin —
Upstream advisory

USN-6532-1

USNPoC exploitHIGH2023-12-05

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities

CVEs:CVE-2023-5717CVE-2023-20593CVE-2023-31085CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-42754CVE-2023-45862CVE-2023-45871

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:16.04:LTS linux —
linux-aws affected Ubuntu:Pro:14.04:LTS linux-aws —
linux-aws affected Ubuntu:Pro:16.04:LTS linux-aws —
linux-kvm affected Ubuntu:Pro:16.04:LTS linux-kvm —
linux-lts-xenial affected Ubuntu:Pro:14.04:LTS linux-lts-xenial —
Upstream advisory

USN-6558-1

USNPoC exploitHIGH2023-12-14

audiofile vulnerabilities

CVEs:CVE-2018-13440CVE-2018-17095CVE-2019-13147CVE-2022-24599

Affected products

ProductStatusVendorPackageEcosystem
audiofile affected Ubuntu:22.04:LTS audiofile —
audiofile affected Ubuntu:20.04:LTS audiofile —
audiofile affected Ubuntu:Pro:18.04:LTS audiofile —
audiofile affected Ubuntu:Pro:14.04:LTS audiofile —
audiofile affected Ubuntu:Pro:16.04:LTS audiofile —
Upstream advisory

USN-6538-1

USNPoC exploitCRITICAL2023-12-06

postgresql-12, postgresql-14, postgresql-15 vulnerabilities

CVEs:CVE-2023-5868CVE-2023-5869CVE-2023-5870

Affected products

ProductStatusVendorPackageEcosystem
postgresql-12 affected Ubuntu:20.04:LTS postgresql-12 —
postgresql-14 affected Ubuntu:22.04:LTS postgresql-14 —
Upstream advisory

USN-6542-1

USNPoC exploitMEDIUM2023-12-07

tinyxml vulnerability

CVEs:CVE-2021-42260

Affected products

ProductStatusVendorPackageEcosystem
tinyxml affected Ubuntu:Pro:16.04:LTS tinyxml —
tinyxml affected Ubuntu:Pro:18.04:LTS tinyxml —
tinyxml affected Ubuntu:20.04:LTS tinyxml —
Upstream advisory

USN-6541-1

USNPoC exploitHIGH2023-12-07

glibc vulnerabilities

CVEs:CVE-2023-4806CVE-2023-4813CVE-2023-5156

Affected products

ProductStatusVendorPackageEcosystem
glibc affected Ubuntu:22.04:LTS glibc —
glibc affected Ubuntu:Pro:18.04:LTS glibc —
glibc affected Ubuntu:Pro:16.04:LTS glibc —
glibc affected Ubuntu:20.04:LTS glibc —
Upstream advisory

USN-6539-1

USNPoC exploitHIGH2023-12-06

python-cryptography vulnerabilities

CVEs:CVE-2023-23931CVE-2023-49083

Affected products

ProductStatusVendorPackageEcosystem
python-cryptography affected Ubuntu:22.04:LTS python-cryptography —
python-cryptography affected Ubuntu:20.04:LTS python-cryptography —
python-cryptography affected Ubuntu — —
Upstream advisory

USN-6543-1

USNPoC exploitHIGH2023-12-11

tar vulnerability

CVEs:CVE-2023-39804

Affected products

ProductStatusVendorPackageEcosystem
tar affected Ubuntu:Pro:16.04:LTS tar —
tar affected Ubuntu:20.04:LTS tar —
tar affected Ubuntu:22.04:LTS tar —
tar affected Ubuntu:Pro:14.04:LTS tar —
tar affected Ubuntu:Pro:18.04:LTS tar —
Upstream advisory

USN-6488-2

USNCoalition ESS < 30%CRITICAL2023-12-14

strongswan vulnerability

CVEs:CVE-2023-41913

Affected products

ProductStatusVendorPackageEcosystem
strongswan affected Ubuntu:Pro:18.04:LTS strongswan —
strongswan affected Ubuntu:Pro:16.04:LTS strongswan —
Upstream advisory

USN-6463-2

USNCoalition ESS < 30%NONE2023-12-06

open-vm-tools vulnerabilities

CVEs:CVE-2023-34058CVE-2023-34059

Affected products

ProductStatusVendorPackageEcosystem
open-vm-tools affected Ubuntu:Pro:16.04:LTS open-vm-tools —
open-vm-tools affected Ubuntu:Pro:18.04:LTS open-vm-tools —
Upstream advisory

USN-6553-1

USNAll remaining2023-12-12

pydantic vulnerability

Affected products

ProductStatusVendorPackageEcosystem
pydantic affected Ubuntu:Pro:20.04:LTS pydantic —
Upstream advisory

USN-6552-1

USNAll remaining2023-12-12

netatalk vulnerability

Affected products

ProductStatusVendorPackageEcosystem
netatalk affected Ubuntu:22.04:LTS netatalk —
netatalk affected Ubuntu:20.04:LTS netatalk —
Upstream advisory

USN-6530-1

USNAll remaining2023-12-05

haproxy vulnerability

Affected products

ProductStatusVendorPackageEcosystem
haproxy affected Ubuntu:20.04:LTS haproxy —
haproxy affected Ubuntu:22.04:LTS haproxy —
Upstream advisory

USN-6509-2

USNAll remainingHIGH2023-12-04

firefox regressions

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:20.04:LTS firefox —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.