Canonical Security Advisories · April 2024 — Canonical Security Advisories
69 advisories 181 CVEs 6 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2024-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-6754-1

USNExploitedCISA KEV listedCRITICAL2024-04-25

nghttp2 vulnerabilities

CVEs:CVE-2019-9511CVE-2019-9513CVE-2023-44487CVE-2024-28182

Affected products

ProductStatusVendorPackageEcosystem
nghttp2 affected Ubuntu:22.04:LTS nghttp2
nghttp2 affected Ubuntu:20.04:LTS nghttp2
nghttp2 affected Ubuntu:Pro:16.04:LTS nghttp2
nghttp2 affected Ubuntu:Pro:18.04:LTS nghttp2
Upstream advisory

USN-6720-1

USNExploitedCISA KEV listedHIGH2024-04-02

cacti vulnerability

CVEs:CVE-2023-39361

Affected products

ProductStatusVendorPackageEcosystem
cacti affected Ubuntu
cacti affected Ubuntu:Pro:22.04:LTS cacti
Upstream advisory

LSN-0103-1

USNExploitedCISA KEV listed2024-04-30

Kernel Live Patch Security Notice

CVEs:CVE-2023-4569CVE-2023-6817CVE-2023-51781CVE-2024-0193CVE-2024-1085CVE-2024-1086CVE-2024-26597

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:22.04:LTS linux
linux affected Ubuntu:Pro:20.04:LTS linux
linux-aws affected Ubuntu:Pro:20.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:Pro:20.04:LTS linux-aws-5.15
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-aws-6.5 affected Ubuntu:Pro:22.04:LTS linux-aws-6.5
linux-azure affected Ubuntu:Pro:22.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-azure-6.5 affected Ubuntu:Pro:22.04:LTS linux-azure-6.5
linux-gcp affected Ubuntu:Pro:22.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:20.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:Pro:20.04:LTS linux-gcp-5.15
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gcp-6.5 affected Ubuntu:Pro:22.04:LTS linux-gcp-6.5
linux-gke affected Ubuntu:Pro:20.04:LTS linux-gke
linux-gke affected Ubuntu:Pro:22.04:LTS linux-gke
linux-hwe-5.15 affected Ubuntu:Pro:20.04:LTS linux-hwe-5.15
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-hwe-6.5 affected Ubuntu:Pro:22.04:LTS linux-hwe-6.5
linux-ibm affected Ubuntu:Pro:22.04:LTS linux-ibm
linux-ibm-5.15 affected Ubuntu:Pro:20.04:LTS linux-ibm-5.15
linux-lowlatency-hwe-5.15 affected Ubuntu:Pro:20.04:LTS linux-lowlatency-hwe-5.15
Upstream advisory

LSN-0102-1

USNExploitedCISA KEV listed2024-04-03

Kernel Live Patch Security Notice

CVEs:CVE-2023-1872CVE-2023-4569CVE-2023-6176CVE-2023-51781CVE-2024-0646CVE-2024-1086

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:16.04:LTS linux
linux affected Ubuntu:Pro:18.04:LTS linux
linux affected Ubuntu:Pro:22.04:LTS linux
linux affected Ubuntu:Pro:20.04:LTS linux
linux-aws affected Ubuntu:Pro:22.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:20.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:16.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:18.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:Pro:20.04:LTS linux-aws-5.15
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-aws-6.5 affected Ubuntu:Pro:22.04:LTS linux-aws-6.5
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-azure affected Ubuntu:Pro:20.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:22.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
linux-azure-4.15 affected Ubuntu:Pro:18.04:LTS linux-azure-4.15
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-azure-6.5 affected Ubuntu:Pro:22.04:LTS linux-azure-6.5
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:20.04:LTS linux-gcp
linux-gcp affected Ubuntu:Pro:22.04:LTS linux-gcp
linux-gcp-4.15 affected Ubuntu:Pro:18.04:LTS linux-gcp-4.15
linux-gcp-5.15 affected Ubuntu:Pro:20.04:LTS linux-gcp-5.15
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gcp-6.5 affected Ubuntu:Pro:22.04:LTS linux-gcp-6.5
linux-gke affected Ubuntu:Pro:20.04:LTS linux-gke
linux-gke affected Ubuntu:Pro:22.04:LTS linux-gke
linux-gke-5.15 affected Ubuntu:Pro:20.04:LTS linux-gke-5.15
linux-gkeop affected Ubuntu:Pro:20.04:LTS linux-gkeop
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-hwe-5.15 affected Ubuntu:Pro:20.04:LTS linux-hwe-5.15
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-hwe-6.5 affected Ubuntu:Pro:22.04:LTS linux-hwe-6.5
linux-ibm affected Ubuntu:Pro:20.04:LTS linux-ibm
linux-ibm affected Ubuntu:Pro:22.04:LTS linux-ibm
linux-ibm-5.15 affected Ubuntu:Pro:20.04:LTS linux-ibm-5.15
linux-lowlatency affected Ubuntu:Pro:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:Pro:20.04:LTS linux-lowlatency-hwe-5.15
linux-lts-xenial affected Ubuntu:Pro:14.04:LTS linux-lts-xenial
Upstream advisory

USN-6738-1

USNExploitedVulnCheck KEV listedNONE2024-04-22

lxd vulnerability

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
lxd affected Ubuntu:Pro:18.04:LTS lxd
lxd affected Ubuntu:Pro:16.04:LTS lxd
Upstream advisory

USN-6737-2

USNWeaponized exploitCRITICAL2024-04-29

glibc vulnerability

CVEs:CVE-2024-2961

Affected products

ProductStatusVendorPackageEcosystem
glibc affected Ubuntu:24.04:LTS glibc
Upstream advisory

USN-6737-1

USNWeaponized exploitCRITICAL2024-04-18

glibc vulnerability

CVEs:CVE-2024-2961

Affected products

ProductStatusVendorPackageEcosystem
glibc affected Ubuntu:20.04:LTS glibc
glibc affected Ubuntu:22.04:LTS glibc
Upstream advisory

USN-6722-1

USNWeaponized exploit2024-04-08

python-django vulnerability

CVEs:CVE-2019-19844

Affected products

ProductStatusVendorPackageEcosystem
python-django affected Ubuntu:Pro:14.04:LTS python-django
Upstream advisory

USN-6740-1

USNWeaponized exploitHIGH2024-04-19

linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities

CVEs:CVE-2023-1382CVE-2023-1838CVE-2023-1998CVE-2023-6915CVE-2023-24023CVE-2023-51043CVE-2023-51779CVE-2023-52429CVE-2023-52445CVE-2023-52451CVE-2023-52464CVE-2023-52600CVE-2023-52603CVE-2024-0639CVE-2024-23851

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:18.04:LTS linux
linux-aws affected Ubuntu:Pro:18.04:LTS linux-aws
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure
linux-azure-4.15 affected Ubuntu:Pro:18.04:LTS linux-azure-4.15
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp
linux-gcp-4.15 affected Ubuntu:Pro:18.04:LTS linux-gcp-4.15
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-kvm affected Ubuntu:Pro:18.04:LTS linux-kvm
linux-oracle affected Ubuntu:Pro:16.04:LTS linux-oracle
linux-oracle affected Ubuntu:Pro:18.04:LTS linux-oracle
Upstream advisory

USN-6739-1

USNWeaponized exploitHIGH2024-04-19

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities

CVEs:CVE-2019-25162CVE-2021-46936CVE-2021-46955CVE-2021-46966CVE-2021-46990CVE-2022-20422CVE-2023-1382CVE-2023-1998CVE-2023-24023CVE-2023-51043CVE-2023-51779CVE-2023-52429CVE-2023-52445CVE-2023-52451CVE-2023-52600CVE-2023-52603CVE-2024-23851

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:16.04:LTS linux
linux-aws affected Ubuntu:Pro:14.04:LTS linux-aws
linux-aws affected Ubuntu:Pro:16.04:LTS linux-aws
linux-kvm affected Ubuntu:Pro:16.04:LTS linux-kvm
linux-lts-xenial affected Ubuntu:Pro:14.04:LTS linux-lts-xenial
Upstream advisory

USN-6725-2

USNActive exploitation (sightings)HIGH2024-04-16

linux-aws, linux-aws-5.15 vulnerabilities

CVEs:CVE-2023-1194CVE-2023-3867CVE-2023-32254CVE-2023-32258CVE-2023-38427CVE-2023-38430CVE-2023-38431CVE-2023-46838CVE-2023-52340CVE-2023-52429CVE-2023-52436CVE-2023-52438CVE-2023-52439CVE-2023-52441CVE-2023-52442CVE-2023-52443CVE-2023-52444CVE-2023-52445CVE-2023-52448CVE-2023-52449CVE-2023-52451CVE-2023-52454CVE-2023-52456CVE-2023-52457CVE-2023-52458CVE-2023-52462CVE-2023-52463CVE-2023-52464CVE-2023-52467CVE-2023-52469CVE-2023-52470CVE-2023-52480CVE-2023-52609CVE-2023-52610CVE-2023-52612CVE-2024-22705CVE-2024-23850CVE-2024-23851CVE-2024-24860CVE-2024-26586CVE-2024-26589CVE-2024-26591CVE-2024-26597CVE-2024-26598CVE-2024-26631CVE-2024-26633

Affected products

ProductStatusVendorPackageEcosystem
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
Upstream advisory

USN-6725-1

USNActive exploitation (sightings)HIGH2024-04-09

linux, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities

CVEs:CVE-2023-1194CVE-2023-3867CVE-2023-32254CVE-2023-32258CVE-2023-38427CVE-2023-38430CVE-2023-38431CVE-2023-46838CVE-2023-52340CVE-2023-52429CVE-2023-52436CVE-2023-52438CVE-2023-52439CVE-2023-52441CVE-2023-52442CVE-2023-52443CVE-2023-52444CVE-2023-52445CVE-2023-52448CVE-2023-52449CVE-2023-52451CVE-2023-52454CVE-2023-52456CVE-2023-52457CVE-2023-52458CVE-2023-52462CVE-2023-52463CVE-2023-52464CVE-2023-52467CVE-2023-52469CVE-2023-52470CVE-2023-52480CVE-2023-52609CVE-2023-52610CVE-2023-52612CVE-2024-22705CVE-2024-23850CVE-2024-23851CVE-2024-24860CVE-2024-26586CVE-2024-26589CVE-2024-26591CVE-2024-26597CVE-2024-26598CVE-2024-26631CVE-2024-26633

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-azure-fde affected Ubuntu:22.04:LTS linux-azure-fde
linux-azure-fde-5.15 affected Ubuntu:20.04:LTS linux-azure-fde-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-gkeop-5.15 affected Ubuntu:20.04:LTS linux-gkeop-5.15
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-ibm-5.15 affected Ubuntu:20.04:LTS linux-ibm-5.15
linux-intel-iotg affected Ubuntu:22.04:LTS linux-intel-iotg
linux-intel-iotg-5.15 affected Ubuntu:20.04:LTS linux-intel-iotg-5.15
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-nvidia affected Ubuntu:22.04:LTS linux-nvidia
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-6731-1

USNActive exploitation (sightings)CRITICAL2024-04-15

yard vulnerabilities

CVEs:CVE-2017-17042CVE-2019-1020001CVE-2024-27285

Affected products

ProductStatusVendorPackageEcosystem
yard affected Ubuntu:Pro:16.04:LTS yard
yard affected Ubuntu:20.04:LTS yard
yard affected Ubuntu:22.04:LTS yard
yard affected Ubuntu:Pro:18.04:LTS yard
yard affected Ubuntu
Upstream advisory

USN-6721-1

USNActive exploitation (sightings)HIGH2024-04-04

xorg-server, xwayland vulnerabilities

CVEs:CVE-2024-31080CVE-2024-31081CVE-2024-31082CVE-2024-31083

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:22.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:14.04:LTS xorg-server
xorg-server affected Ubuntu:20.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:16.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:18.04:LTS xorg-server
xwayland affected Ubuntu:22.04:LTS xwayland
Upstream advisory

USN-6753-1

USNActive exploitation (sightings)HIGH2024-04-25

cryptojs vulnerability

CVEs:CVE-2023-46233

Affected products

ProductStatusVendorPackageEcosystem
cryptojs affected Ubuntu:Pro:18.04:LTS cryptojs
cryptojs affected Ubuntu:20.04:LTS cryptojs
cryptojs affected Ubuntu:Pro:16.04:LTS cryptojs
cryptojs affected Ubuntu:Pro:22.04:LTS cryptojs
Upstream advisory

USN-6723-1

USNPoC exploitCRITICAL2024-04-09

bind9 vulnerabilities

CVEs:CVE-2023-50387CVE-2023-50868

Affected products

ProductStatusVendorPackageEcosystem
bind9 affected Ubuntu:Pro:18.04:LTS bind9
bind9 affected Ubuntu:Pro:14.04:LTS bind9
bind9 affected Ubuntu:Pro:16.04:LTS bind9
Upstream advisory

USN-6736-1

USNPoC exploitCRITICAL2024-04-16

klibc vulnerabilities

CVEs:CVE-2016-9840CVE-2016-9841CVE-2018-25032CVE-2022-37434

Affected products

ProductStatusVendorPackageEcosystem
klibc affected Ubuntu:20.04:LTS klibc
klibc affected Ubuntu:Pro:16.04:LTS klibc
klibc affected Ubuntu:Pro:14.04:LTS klibc
klibc affected Ubuntu:22.04:LTS klibc
klibc affected Ubuntu:Pro:18.04:LTS klibc
Upstream advisory

USN-6757-1

USNPoC exploitCRITICAL2024-04-29

php7.0, php7.2, php7.4, php8.1 vulnerabilities

CVEs:CVE-2022-4900CVE-2024-2756CVE-2024-3096

Affected products

ProductStatusVendorPackageEcosystem
php7.0 affected Ubuntu:Pro:16.04:LTS php7.0
php7.2 affected Ubuntu:Pro:18.04:LTS php7.2
php7.4 affected Ubuntu:20.04:LTS php7.4
php8.1 affected Ubuntu:22.04:LTS php8.1
Upstream advisory

USN-6758-1

USNPoC exploitHIGH2024-04-30

node-json5 vulnerability

CVEs:CVE-2022-46175

Affected products

ProductStatusVendorPackageEcosystem
node-json5 affected Ubuntu:Pro:18.04:LTS node-json5
node-json5 affected Ubuntu:20.04:LTS node-json5
node-json5 affected Ubuntu:Pro:22.04:LTS node-json5
Upstream advisory

USN-6735-1

USNPoC exploitMEDIUM2024-04-16

nodejs vulnerabilities

CVEs:CVE-2023-30588CVE-2023-30589CVE-2023-30590

Affected products

ProductStatusVendorPackageEcosystem
nodejs affected Ubuntu:Pro:14.04:LTS nodejs
nodejs affected Ubuntu:22.04:LTS nodejs
nodejs affected Ubuntu:Pro:18.04:LTS nodejs
nodejs affected Node.js
nodejs affected Ubuntu:20.04:LTS nodejs
nodejs affected Ubuntu:Pro:16.04:LTS nodejs
Upstream advisory

USN-6719-2

USNPoC exploitMEDIUM2024-04-10

util-linux vulnerability

CVEs:CVE-2024-28085

Affected products

ProductStatusVendorPackageEcosystem
util-linux affected util-linux
util-linux affected Ubuntu:22.04:LTS util-linux
util-linux affected Ubuntu:20.04:LTS util-linux
Upstream advisory

USN-6742-2

USNPoC exploitNONE2024-04-23

linux-azure, linux-lowlatency, linux-nvidia vulnerabilities

CVEs:CVE-2023-24023CVE-2023-52600CVE-2023-52603CVE-2024-26581

Affected products

ProductStatusVendorPackageEcosystem
linux-azure affected Ubuntu
linux-azure affected Ubuntu:22.04:LTS linux-azure
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-nvidia affected Ubuntu:22.04:LTS linux-nvidia
Upstream advisory

USN-6743-1

USNPoC exploit2024-04-19

linux, linux-aws, linux-aws-6.5, linux-azure, linux-gcp, linux-gcp-6.5, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-nvidia-6.5, linux-oem-6.5, linux-oracle, linux-oracle-6.5, linux-raspi, linux-starfive, linux-starfive-6.5 vulnerabilities

CVEs:CVE-2023-52600CVE-2023-52603CVE-2024-26581CVE-2024-26589CVE-2024-26591

Affected products

ProductStatusVendorPackageEcosystem
linux-aws-6.5 affected Ubuntu:22.04:LTS linux-aws-6.5
linux-gcp-6.5 affected Ubuntu:22.04:LTS linux-gcp-6.5
linux-hwe-6.5 affected Ubuntu:22.04:LTS linux-hwe-6.5
linux-nvidia-6.5 affected Ubuntu:22.04:LTS linux-nvidia-6.5
linux-oem-6.5 affected Ubuntu:22.04:LTS linux-oem-6.5
linux-oracle-6.5 affected Ubuntu:22.04:LTS linux-oracle-6.5
linux-starfive-6.5 affected Ubuntu:22.04:LTS linux-starfive-6.5
Upstream advisory

USN-6742-1

USNPoC exploitNONE2024-04-19

linux, linux-aws, linux-aws-5.15, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities

CVEs:CVE-2023-24023CVE-2023-52600CVE-2023-52603CVE-2024-26581

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-azure-5.15 affected Ubuntu:20.04:LTS linux-azure-5.15
linux-azure-fde affected Ubuntu:22.04:LTS linux-azure-fde
linux-azure-fde-5.15 affected Ubuntu:20.04:LTS linux-azure-fde-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gke affected Ubuntu:22.04:LTS linux-gke
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-gkeop-5.15 affected Ubuntu:20.04:LTS linux-gkeop-5.15
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-ibm-5.15 affected Ubuntu:20.04:LTS linux-ibm-5.15
linux-intel-iotg affected Ubuntu:22.04:LTS linux-intel-iotg
linux-intel-iotg-5.15 affected Ubuntu:20.04:LTS linux-intel-iotg-5.15
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
Upstream advisory

USN-6741-1

USNPoC exploitNONE2024-04-19

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities

CVEs:CVE-2023-24023CVE-2023-52600CVE-2023-52603CVE-2024-26581CVE-2024-26589

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-iot affected Ubuntu:20.04:LTS linux-iot
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.4 affected Ubuntu:Pro:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4
linux-xilinx-zynqmp affected Ubuntu:20.04:LTS linux-xilinx-zynqmp
Upstream advisory

USN-6746-1

USNPoC exploitHIGH2024-04-23

google-guest-agent, google-osconfig-agent vulnerability

CVEs:CVE-2024-24786

Affected products

ProductStatusVendorPackageEcosystem
google-guest-agent affected Ubuntu:22.04:LTS google-guest-agent
google-osconfig-agent affected Ubuntu:22.04:LTS google-osconfig-agent
Upstream advisory

USN-6726-3

USNPoC exploitMEDIUM2024-04-17

linux-xilinx-zynqmp vulnerabilities

CVEs:CVE-2023-46838CVE-2023-52340CVE-2023-52429CVE-2023-52436CVE-2023-52438CVE-2023-52439CVE-2023-52443CVE-2023-52444CVE-2023-52445CVE-2023-52448CVE-2023-52449CVE-2023-52451CVE-2023-52454CVE-2023-52457CVE-2023-52464CVE-2023-52469CVE-2023-52470CVE-2023-52609CVE-2023-52612CVE-2024-0607CVE-2024-23851CVE-2024-26597CVE-2024-26633

Affected products

ProductStatusVendorPackageEcosystem
linux-xilinx-zynqmp affected Ubuntu:20.04:LTS linux-xilinx-zynqmp
Upstream advisory

USN-6726-2

USNPoC exploitMEDIUM2024-04-16

linux-iot vulnerabilities

CVEs:CVE-2023-46838CVE-2023-52340CVE-2023-52429CVE-2023-52436CVE-2023-52438CVE-2023-52439CVE-2023-52443CVE-2023-52444CVE-2023-52445CVE-2023-52448CVE-2023-52449CVE-2023-52451CVE-2023-52454CVE-2023-52457CVE-2023-52464CVE-2023-52469CVE-2023-52470CVE-2023-52609CVE-2023-52612CVE-2024-0607CVE-2024-23851CVE-2024-26597CVE-2024-26633

Affected products

ProductStatusVendorPackageEcosystem
linux-iot affected Ubuntu:20.04:LTS linux-iot
Upstream advisory

USN-6726-1

USNPoC exploitMEDIUM2024-04-09

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities

CVEs:CVE-2023-46838CVE-2023-52340CVE-2023-52429CVE-2023-52436CVE-2023-52438CVE-2023-52439CVE-2023-52443CVE-2023-52444CVE-2023-52445CVE-2023-52448CVE-2023-52449CVE-2023-52451CVE-2023-52454CVE-2023-52457CVE-2023-52464CVE-2023-52469CVE-2023-52470CVE-2023-52609CVE-2023-52612CVE-2024-0607CVE-2024-23851CVE-2024-26597CVE-2024-26633

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-azure affected Ubuntu:20.04:LTS linux-azure
linux-azure-5.4 affected Ubuntu:Pro:18.04:LTS linux-azure-5.4
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.4 affected Ubuntu:Pro:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-6724-1

USNPoC exploitHIGH2024-04-09

linux, linux-aws, linux-azure, linux-azure-6.5, linux-gcp, linux-gcp-6.5, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-oracle-6.5, linux-starfive, linux-starfive-6.5 vulnerabilities

CVEs:CVE-2023-6610CVE-2023-46838CVE-2023-50431CVE-2023-52429CVE-2023-52434CVE-2023-52435CVE-2023-52436CVE-2023-52438CVE-2023-52439CVE-2024-22705CVE-2024-23850CVE-2024-23851

Affected products

ProductStatusVendorPackageEcosystem
linux-azure-6.5 affected Ubuntu:22.04:LTS linux-azure-6.5
linux-gcp-6.5 affected Ubuntu:22.04:LTS linux-gcp-6.5
linux-hwe-6.5 affected Ubuntu:22.04:LTS linux-hwe-6.5
linux-lowlatency-hwe-6.5 affected Ubuntu:22.04:LTS linux-lowlatency-hwe-6.5
linux-oem-6.5 affected Ubuntu:22.04:LTS linux-oem-6.5
linux-oracle-6.5 affected Ubuntu:22.04:LTS linux-oracle-6.5
linux-starfive-6.5 affected Ubuntu:22.04:LTS linux-starfive-6.5
Upstream advisory

USN-6744-1

USNPoC exploitHIGH2024-04-22

pillow vulnerability

CVEs:CVE-2024-28219

Affected products

ProductStatusVendorPackageEcosystem
pillow affected Ubuntu:Pro:18.04:LTS pillow
pillow affected Ubuntu:Pro:16.04:LTS pillow
pillow affected Ubuntu:22.04:LTS pillow
pillow affected Ubuntu:20.04:LTS pillow
pillow affected Ubuntu:Pro:14.04:LTS pillow
Upstream advisory

USN-6756-1

USNPoC exploitHIGH2024-04-29

less vulnerability

CVEs:CVE-2024-32487

Affected products

ProductStatusVendorPackageEcosystem
less affected Ubuntu:Pro:18.04:LTS less
less affected Ubuntu:24.04:LTS less
less affected Ubuntu:20.04:LTS less
less affected Ubuntu:22.04:LTS less
less affected Ubuntu:Pro:14.04:LTS less
less affected Ubuntu:Pro:16.04:LTS less
Upstream advisory

USN-6761-1

USNPoC exploitHIGH2024-04-30

anope vulnerability

CVEs:CVE-2024-30187

Affected products

ProductStatusVendorPackageEcosystem
anope affected Ubuntu:Pro:16.04:LTS anope
anope affected Ubuntu:20.04:LTS anope
anope affected Ubuntu:22.04:LTS anope
anope affected Ubuntu:Pro:18.04:LTS anope
anope affected Ubuntu:24.04:LTS anope
Upstream advisory

USN-6730-1

USNCoalition ESS < 30%CRITICAL2024-04-11

maven-shared-utils vulnerability

CVEs:CVE-2022-29599

Affected products

ProductStatusVendorPackageEcosystem
maven-shared-utils affected Ubuntu:Pro:16.04:LTS maven-shared-utils
maven-shared-utils affected Ubuntu:22.04:LTS maven-shared-utils
maven-shared-utils affected Ubuntu:Pro:18.04:LTS maven-shared-utils
maven-shared-utils affected Ubuntu:Pro:14.04:LTS maven-shared-utils
maven-shared-utils affected Ubuntu:20.04:LTS maven-shared-utils
Upstream advisory

USN-6751-1

USNCoalition ESS < 30%HIGH2024-04-25

zabbix vulnerabilities

CVEs:CVE-2022-35229CVE-2022-35230

Affected products

ProductStatusVendorPackageEcosystem
zabbix affected Ubuntu:Pro:20.04:LTS zabbix
zabbix affected Ubuntu:Pro:18.04:LTS zabbix
zabbix affected Ubuntu:Pro:22.04:LTS zabbix
zabbix affected Ubuntu:Pro:16.04:LTS zabbix
zabbix affected Ubuntu:Pro:14.04:LTS zabbix
Upstream advisory

UBUNTU-CVE-2020-25730

USNCoalition ESS < 30%HIGH2024-04-04

CVEs:CVE-2020-25730

Affected products

ProductStatusVendorPackageEcosystem
zoneminder affected Ubuntu:24.04:LTS zoneminder
zoneminder affected Ubuntu:Pro:16.04:LTS zoneminder
zoneminder affected Ubuntu:Pro:20.04:LTS zoneminder
zoneminder affected Ubuntu:Pro:22.04:LTS zoneminder
zoneminder affected Ubuntu:25.10 zoneminder
Upstream advisory

UBUNTU-CVE-2020-36829

USNCoalition ESS < 30%HIGH2024-04-08

CVEs:CVE-2020-36829

Affected products

ProductStatusVendorPackageEcosystem
libmojolicious-perl affected Ubuntu:20.04:LTS libmojolicious-perl
libmojolicious-perl affected Ubuntu:18.04:LTS libmojolicious-perl
libmojolicious-perl affected Ubuntu:16.04:LTS libmojolicious-perl
Upstream advisory

USN-6745-1

USNCoalition ESS < 30%CRITICAL2024-04-22

percona-xtrabackup vulnerability

CVEs:CVE-2022-25834

Affected products

ProductStatusVendorPackageEcosystem
percona-xtrabackup affected Ubuntu:Pro:16.04:LTS percona-xtrabackup
percona-xtrabackup affected Ubuntu:Pro:18.04:LTS percona-xtrabackup
Upstream advisory

USN-6760-1

USNCoalition ESS < 30%MEDIUM2024-04-30

gerbv vulnerability

CVEs:CVE-2023-4508

Affected products

ProductStatusVendorPackageEcosystem
gerbv affected Ubuntu:Pro:22.04:LTS gerbv
gerbv affected Ubuntu:Pro:14.04:LTS gerbv
gerbv affected Ubuntu:Pro:18.04:LTS gerbv
gerbv affected Ubuntu:Pro:16.04:LTS gerbv
gerbv affected Ubuntu:20.04:LTS gerbv
Upstream advisory

USN-6744-3

USNAll remaining2024-04-29

pillow vulnerability

Affected products

ProductStatusVendorPackageEcosystem
pillow affected Ubuntu:24.04:LTS pillow
Upstream advisory

USN-6755-1

USNAll remaining2024-04-29

cpio vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
cpio affected Ubuntu:22.04:LTS cpio
cpio affected Ubuntu:20.04:LTS cpio
Upstream advisory

USN-6748-1

USNAll remaining2024-04-24

ruby-sanitize vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
ruby-sanitize affected Ubuntu:22.04:LTS ruby-sanitize
ruby-sanitize affected Ubuntu:20.04:LTS ruby-sanitize
Upstream advisory

USN-6744-2

USNAll remaining2024-04-22

pillow vulnerability

Affected products

ProductStatusVendorPackageEcosystem
pillow-python2 affected Ubuntu:Pro:20.04:LTS pillow-python2
Upstream advisory

USN-6727-2

USNAll remainingNONE2024-04-11

nss regression

Affected products

ProductStatusVendorPackageEcosystem
nss affected Ubuntu:20.04:LTS nss
nss affected Ubuntu:22.04:LTS nss
Upstream advisory

USN-6728-2

USNAll remaining2024-04-11

squid regression

Affected products

ProductStatusVendorPackageEcosystem
squid affected Ubuntu:20.04:LTS squid
Upstream advisory

USN-6721-2

USNAll remainingHIGH2024-04-09

xorg-server, xwayland regression

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:Pro:18.04:LTS xorg-server
xorg-server affected Ubuntu:22.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:14.04:LTS xorg-server
xorg-server affected Ubuntu:20.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:16.04:LTS xorg-server
xwayland affected Ubuntu:22.04:LTS xwayland
Upstream advisory

USN-6710-2

USNAll remainingHIGH2024-04-04

firefox regressions

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.