Canonical Security Advisories · December 2023 — Canonical Security Advisories
44 advisories 71 CVEs 2 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2023-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-6561-1

USNExploitedVulnCheck KEV listedCRITICAL2023-12-19

libssh vulnerability

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
libssh affected Ubuntu:22.04:LTS libssh
libssh affected Ubuntu:20.04:LTS libssh
Upstream advisory

USN-6560-1

USNExploitedVulnCheck KEV listedCRITICAL2023-12-19

openssh vulnerabilities

CVEs:CVE-2023-28531CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
openssh affected Ubuntu:22.04:LTS openssh
openssh affected Ubuntu:20.04:LTS openssh
Upstream advisory

USN-6555-2

USNActive exploitation (sightings)CRITICAL2023-12-13

xorg-server vulnerabilities

CVEs:CVE-2023-6377CVE-2023-6478

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:Pro:18.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:16.04:LTS xorg-server
Upstream advisory

USN-6555-1

USNActive exploitation (sightings)CRITICAL2023-12-13

xorg-server, xwayland vulnerabilities

CVEs:CVE-2023-6377CVE-2023-6478

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:20.04:LTS xorg-server
xorg-server affected Ubuntu:22.04:LTS xorg-server
xwayland affected Ubuntu:22.04:LTS xwayland
Upstream advisory

USN-6554-1

USNActive exploitation (sightings)NONE2023-12-13

gnome-control-center vulnerability

CVEs:CVE-2023-5616

Affected products

ProductStatusVendorPackageEcosystem
gnome-control-center affected Ubuntu:22.04:LTS gnome-control-center
gnome-control-center affected Ubuntu:20.04:LTS gnome-control-center
Upstream advisory

USN-6534-3

USNPoC exploitHIGH2023-12-13

linux-hwe-6.2, linux-lowlatency-hwe-6.2, linux-nvidia-6.2 vulnerabilities

CVEs:CVE-2023-3773CVE-2023-5158CVE-2023-5178CVE-2023-5717CVE-2023-6039CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-39198CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux-hwe-6.2 affected Ubuntu:22.04:LTS linux-hwe-6.2
linux-lowlatency-hwe-6.2 affected Ubuntu:22.04:LTS linux-lowlatency-hwe-6.2
linux-nvidia-6.2 affected Ubuntu:22.04:LTS linux-nvidia-6.2
Upstream advisory

USN-6548-2

USNPoC exploitHIGH2023-12-12

linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2023-3006CVE-2023-5178CVE-2023-5717CVE-2023-6176CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux-oracle-5.4 affected Ubuntu:Pro:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-6548-1

USNPoC exploitHIGH2023-12-11

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-xilinx-zynqmp vulnerabilities

CVEs:CVE-2023-3006CVE-2023-5178CVE-2023-5717CVE-2023-6176CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-xilinx-zynqmp affected Ubuntu:20.04:LTS linux-xilinx-zynqmp
Upstream advisory

USN-6549-1

USNPoC exploitHIGH2023-12-11

linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gke, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-kvm, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities

CVEs:CVE-2023-3773CVE-2023-5158CVE-2023-5178CVE-2023-5717CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-39198CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-azure-fde affected Ubuntu:22.04:LTS linux-azure-fde
linux-azure-fde-5.15 affected Ubuntu:20.04:LTS linux-azure-fde-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-ibm-5.15 affected Ubuntu:20.04:LTS linux-ibm-5.15
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-nvidia affected Ubuntu:22.04:LTS linux-nvidia
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-6534-1

USNPoC exploitHIGH2023-12-05

linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-lowlatency, linux-oracle, linux-raspi, linux-starfive vulnerabilities

CVEs:CVE-2023-3773CVE-2023-5158CVE-2023-5178CVE-2023-5717CVE-2023-6039CVE-2023-37453CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-39198CVE-2023-42754

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-6.2 affected Ubuntu:22.04:LTS linux-aws-6.2
linux-azure-6.2 affected Ubuntu:22.04:LTS linux-azure-6.2
linux-azure-fde-6.2 affected Ubuntu:22.04:LTS linux-azure-fde-6.2
Upstream advisory

USN-6532-1

USNPoC exploitHIGH2023-12-05

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities

CVEs:CVE-2023-5717CVE-2023-20593CVE-2023-31085CVE-2023-39189CVE-2023-39192CVE-2023-39193CVE-2023-39194CVE-2023-42754CVE-2023-45862CVE-2023-45871

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:16.04:LTS linux
linux-aws affected Ubuntu:Pro:14.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:16.04:LTS linux-aws
linux-kvm affected Ubuntu:Pro:16.04:LTS linux-kvm
linux-lts-xenial affected Ubuntu:Pro:14.04:LTS linux-lts-xenial
Upstream advisory

USN-6550-1

USNPoC exploitCRITICAL2023-12-12

postfixadmin vulnerabilities

CVEs:CVE-2022-29221CVE-2022-31129CVE-2023-28447

Affected products

ProductStatusVendorPackageEcosystem
postfixadmin affected Ubuntu:Pro:20.04:LTS postfixadmin
postfixadmin affected Ubuntu:Pro:22.04:LTS postfixadmin
postfixadmin affected Ubuntu:Pro:18.04:LTS postfixadmin
Upstream advisory

USN-6558-1

USNPoC exploitHIGH2023-12-14

audiofile vulnerabilities

CVEs:CVE-2018-13440CVE-2018-17095CVE-2019-13147CVE-2022-24599

Affected products

ProductStatusVendorPackageEcosystem
audiofile affected Ubuntu:22.04:LTS audiofile
audiofile affected Ubuntu:20.04:LTS audiofile
audiofile affected Ubuntu:Pro:18.04:LTS audiofile
audiofile affected Ubuntu:Pro:14.04:LTS audiofile
audiofile affected Ubuntu:Pro:16.04:LTS audiofile
Upstream advisory

USN-6538-1

USNPoC exploitCRITICAL2023-12-06

postgresql-12, postgresql-14, postgresql-15 vulnerabilities

CVEs:CVE-2023-5868CVE-2023-5869CVE-2023-5870

Affected products

ProductStatusVendorPackageEcosystem
postgresql-12 affected Ubuntu:20.04:LTS postgresql-12
postgresql-14 affected Ubuntu:22.04:LTS postgresql-14
Upstream advisory

USN-6541-1

USNPoC exploitHIGH2023-12-07

glibc vulnerabilities

CVEs:CVE-2023-4806CVE-2023-4813CVE-2023-5156

Affected products

ProductStatusVendorPackageEcosystem
glibc affected Ubuntu:Pro:18.04:LTS glibc
glibc affected Ubuntu:Pro:16.04:LTS glibc
glibc affected Ubuntu:20.04:LTS glibc
glibc affected Ubuntu:22.04:LTS glibc
Upstream advisory

USN-6539-1

USNPoC exploitHIGH2023-12-06

python-cryptography vulnerabilities

CVEs:CVE-2023-23931CVE-2023-49083

Affected products

ProductStatusVendorPackageEcosystem
python-cryptography affected Ubuntu:22.04:LTS python-cryptography
python-cryptography affected Ubuntu:20.04:LTS python-cryptography
Upstream advisory

USN-6488-2

USNAll remaining2023-12-14

strongswan vulnerability

Affected products

ProductStatusVendorPackageEcosystem
strongswan affected Ubuntu:Pro:18.04:LTS strongswan
strongswan affected Ubuntu:Pro:16.04:LTS strongswan
Upstream advisory

USN-6557-1

USNAll remaining2023-12-14

vim vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
vim affected Ubuntu:Pro:16.04:LTS vim
vim affected Ubuntu:Pro:18.04:LTS vim
vim affected Ubuntu:Pro:14.04:LTS vim
vim affected Ubuntu:20.04:LTS vim
vim affected Ubuntu:22.04:LTS vim
Upstream advisory

USN-6546-2

USNAll remaining2023-12-14

libreoffice vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
libreoffice affected Ubuntu:22.04:LTS libreoffice
libreoffice affected Ubuntu:20.04:LTS libreoffice
Upstream advisory

USN-6553-1

USNAll remaining2023-12-12

pydantic vulnerability

Affected products

ProductStatusVendorPackageEcosystem
pydantic affected Ubuntu:Pro:20.04:LTS pydantic
Upstream advisory

USN-6552-1

USNAll remaining2023-12-12

netatalk vulnerability

Affected products

ProductStatusVendorPackageEcosystem
netatalk affected Ubuntu:22.04:LTS netatalk
netatalk affected Ubuntu:20.04:LTS netatalk
Upstream advisory

USN-6551-1

USNAll remaining2023-12-12

ghostscript vulnerability

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Ubuntu:22.04:LTS ghostscript
Upstream advisory

USN-6545-1

USNAll remaining2023-12-11

webkit2gtk vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
webkit2gtk affected Ubuntu:22.04:LTS webkit2gtk
Upstream advisory

USN-6500-2

USNAll remaining2023-12-11

squid3 vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
squid3 affected Ubuntu:Pro:18.04:LTS squid3
squid3 affected Ubuntu:Pro:16.04:LTS squid3
Upstream advisory

USN-6543-1

USNAll remaining2023-12-11

tar vulnerability

Affected products

ProductStatusVendorPackageEcosystem
tar affected Ubuntu:Pro:14.04:LTS tar
tar affected Ubuntu:Pro:16.04:LTS tar
tar affected Ubuntu:20.04:LTS tar
tar affected Ubuntu:22.04:LTS tar
tar affected Ubuntu:Pro:18.04:LTS tar
Upstream advisory

USN-6542-1

USNAll remaining2023-12-07

tinyxml vulnerability

Affected products

ProductStatusVendorPackageEcosystem
tinyxml affected Ubuntu:Pro:16.04:LTS tinyxml
tinyxml affected Ubuntu:Pro:18.04:LTS tinyxml
tinyxml affected Ubuntu:20.04:LTS tinyxml
Upstream advisory

USN-6522-2

USNAll remaining2023-12-07

freerdp2 vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
freerdp2 affected Ubuntu:Pro:18.04:LTS freerdp2
Upstream advisory

USN-6540-1

USNAll remaining2023-12-07

bluez vulnerability

Affected products

ProductStatusVendorPackageEcosystem
bluez affected Ubuntu:22.04:LTS bluez
bluez affected Ubuntu:Pro:16.04:LTS bluez
bluez affected Ubuntu:Pro:18.04:LTS bluez
bluez affected Ubuntu:20.04:LTS bluez
Upstream advisory

USN-6535-1

USNAll remaining2023-12-06

curl vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
curl affected Ubuntu:20.04:LTS curl
curl affected Ubuntu:22.04:LTS curl
Upstream advisory

USN-6463-2

USNAll remaining2023-12-06

open-vm-tools vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
open-vm-tools affected Ubuntu:Pro:16.04:LTS open-vm-tools
open-vm-tools affected Ubuntu:Pro:18.04:LTS open-vm-tools
Upstream advisory

USN-6530-1

USNAll remaining2023-12-05

haproxy vulnerability

Affected products

ProductStatusVendorPackageEcosystem
haproxy affected Ubuntu:20.04:LTS haproxy
haproxy affected Ubuntu:22.04:LTS haproxy
Upstream advisory

USN-6509-2

USNAll remaining2023-12-04

firefox regressions

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.