Canonical Security Advisories · October 2024 — Canonical Security Advisories
74 advisories 433 CVEs 11 EXPLOITED

Ubuntu Security Notices (USN-NNNN-N) for 2024-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 11 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

USN-7067-1

USNExploitedCISA KEV listedCRITICAL2024-10-14

haproxy vulnerability

CVEs:CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
haproxy affected Ubuntu:Pro:18.04:LTS haproxy
Upstream advisory

USN-7066-1

USNExploitedCISA KEV listedCRITICAL2024-10-14

thunderbird vulnerability

CVEs:CVE-2024-9680

Affected products

ProductStatusVendorPackageEcosystem
thunderbird affected Ubuntu:22.04:LTS thunderbird
thunderbird affected Ubuntu:20.04:LTS thunderbird
Upstream advisory

USN-7065-1

USNExploitedCISA KEV listedCRITICAL2024-10-14

firefox vulnerability

CVEs:CVE-2024-9680

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

USN-7069-2

USNExploitedCISA KEV listedNONE2024-10-17

linux-azure vulnerabilities

CVEs:CVE-2023-52510CVE-2023-52528CVE-2024-26602CVE-2024-26641CVE-2024-26754CVE-2024-26810CVE-2024-26812CVE-2024-26960CVE-2024-27051CVE-2024-27436CVE-2024-31076CVE-2024-36971CVE-2024-38602CVE-2024-38611CVE-2024-38621CVE-2024-38627CVE-2024-38630CVE-2024-39487CVE-2024-39494CVE-2024-40901CVE-2024-40941CVE-2024-41073CVE-2024-41097CVE-2024-42089CVE-2024-42157CVE-2024-42223CVE-2024-42229CVE-2024-42244CVE-2024-42271CVE-2024-42280CVE-2024-42284CVE-2024-43858CVE-2024-44940CVE-2024-45016CVE-2024-46673

Affected products

ProductStatusVendorPackageEcosystem
linux-azure affected Ubuntu:Pro:16.04:LTS linux-azure
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure
Upstream advisory

USN-7069-1

USNExploitedCISA KEV listedNONE2024-10-15

linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities

CVEs:CVE-2023-52510CVE-2023-52528CVE-2024-26602CVE-2024-26641CVE-2024-26754CVE-2024-26810CVE-2024-26812CVE-2024-26960CVE-2024-27051CVE-2024-27436CVE-2024-31076CVE-2024-36971CVE-2024-38602CVE-2024-38611CVE-2024-38621CVE-2024-38627CVE-2024-38630CVE-2024-39487CVE-2024-39494CVE-2024-40901CVE-2024-40941CVE-2024-41073CVE-2024-41097CVE-2024-42089CVE-2024-42157CVE-2024-42223CVE-2024-42229CVE-2024-42244CVE-2024-42271CVE-2024-42280CVE-2024-42284CVE-2024-43858CVE-2024-44940CVE-2024-45016CVE-2024-46673

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:Pro:18.04:LTS linux
linux-aws affected Ubuntu:Pro:18.04:LTS linux-aws
linux-aws-hwe affected Ubuntu:Pro:16.04:LTS linux-aws-hwe
linux-azure-4.15 affected Ubuntu:Pro:18.04:LTS linux-azure-4.15
linux-gcp affected Ubuntu:Pro:16.04:LTS linux-gcp
linux-gcp-4.15 affected Ubuntu:Pro:18.04:LTS linux-gcp-4.15
linux-hwe affected Ubuntu:Pro:16.04:LTS linux-hwe
linux-kvm affected Ubuntu:Pro:18.04:LTS linux-kvm
linux-oracle affected Ubuntu:Pro:16.04:LTS linux-oracle
linux-oracle affected Ubuntu:Pro:18.04:LTS linux-oracle
Upstream advisory

USN-7051-1

USNExploitedVulnCheck KEV listedCRITICAL2024-10-02

python-asyncssh vulnerability

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
python-asyncssh affected Ubuntu:20.04:LTS python-asyncssh
python-asyncssh affected Ubuntu:24.04:LTS python-asyncssh
python-asyncssh affected Ubuntu:Pro:22.04:LTS python-asyncssh
Upstream advisory

USN-7043-4

USNExploitedVulnCheck KEV listedCRITICAL2024-10-09

cups-filters vulnerabilities

CVEs:CVE-2024-47076CVE-2024-47176

Affected products

ProductStatusVendorPackageEcosystem
cups-filters affected Ubuntu:20.04:LTS cups-filters
cups-filters affected Ubuntu:22.04:LTS cups-filters
cups-filters affected Ubuntu
Upstream advisory

USN-7042-3

USNExploitedVulnCheck KEV listed2024-10-21

cups-browsed vulnerability

CVEs:CVE-2024-47176

Affected products

ProductStatusVendorPackageEcosystem
cups-browsed affected Ubuntu:24.10 cups-browsed
Upstream advisory

USN-7043-3

USNExploitedVulnCheck KEV listedCRITICAL2024-10-07

cups-filters vulnerability

CVEs:CVE-2024-47176

Affected products

ProductStatusVendorPackageEcosystem
cups-filters affected Ubuntu:Pro:16.04:LTS cups-filters
Upstream advisory

USN-7043-2

USNExploitedVulnCheck KEV listedCRITICAL2024-10-01

cups-filters vulnerability

CVEs:CVE-2024-47176

Affected products

ProductStatusVendorPackageEcosystem
cups-filters affected Ubuntu:Pro:18.04:LTS cups-filters
Upstream advisory

USN-7041-3

USNWeaponized exploitCRITICAL2024-10-07

cups vulnerability

CVEs:CVE-2024-47175

Affected products

ProductStatusVendorPackageEcosystem
cups affected Ubuntu:Pro:16.04:LTS cups
Upstream advisory

USN-7041-2

USNWeaponized exploitCRITICAL2024-10-01

cups vulnerability

CVEs:CVE-2024-47175

Affected products

ProductStatusVendorPackageEcosystem
cups affected Ubuntu:Pro:18.04:LTS cups
Upstream advisory

USN-7088-1

USNWeaponized exploitHIGH2024-10-31

linux, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4 vulnerabilities

CVEs:CVE-2021-47212CVE-2022-36402CVE-2023-52531CVE-2023-52614CVE-2023-52918CVE-2024-26607CVE-2024-26640CVE-2024-26641CVE-2024-26668CVE-2024-26669CVE-2024-26800CVE-2024-26885CVE-2024-26891CVE-2024-27051CVE-2024-35848CVE-2024-36484CVE-2024-38602CVE-2024-38611CVE-2024-40929CVE-2024-41011CVE-2024-41012CVE-2024-41015CVE-2024-41017CVE-2024-41020CVE-2024-41022CVE-2024-41042CVE-2024-41059CVE-2024-41063CVE-2024-41064CVE-2024-41065CVE-2024-41068CVE-2024-41070CVE-2024-41071CVE-2024-41072CVE-2024-41073CVE-2024-41081CVE-2024-41090CVE-2024-41091CVE-2024-41098CVE-2024-42131CVE-2024-42229CVE-2024-42244CVE-2024-42246CVE-2024-42259CVE-2024-42265CVE-2024-42271CVE-2024-42276CVE-2024-42280CVE-2024-42281CVE-2024-42283CVE-2024-42284CVE-2024-42285CVE-2024-42286CVE-2024-42287CVE-2024-42288CVE-2024-42289CVE-2024-42290CVE-2024-42292CVE-2024-42295CVE-2024-42297CVE-2024-42301CVE-2024-42304CVE-2024-42305CVE-2024-42306CVE-2024-42309CVE-2024-42310CVE-2024-42311CVE-2024-42313CVE-2024-43829CVE-2024-43830CVE-2024-43835CVE-2024-43839CVE-2024-43841CVE-2024-43846CVE-2024-43853CVE-2024-43854CVE-2024-43856CVE-2024-43858CVE-2024-43860CVE-2024-43861CVE-2024-43867CVE-2024-43871CVE-2024-43879CVE-2024-43880CVE-2024-43882CVE-2024-43883CVE-2024-43884CVE-2024-43890CVE-2024-43893CVE-2024-43894CVE-2024-43908CVE-2024-43914CVE-2024-44935CVE-2024-44944CVE-2024-44946CVE-2024-44947CVE-2024-44948CVE-2024-44952CVE-2024-44954CVE-2024-44960CVE-2024-44965CVE-2024-44969CVE-2024-44987CVE-2024-44988CVE-2024-44995CVE-2024-44998CVE-2024-44999CVE-2024-45003CVE-2024-45006CVE-2024-45008CVE-2024-45021CVE-2024-45025CVE-2024-45026CVE-2024-45028CVE-2024-46673CVE-2024-46675CVE-2024-46676CVE-2024-46677CVE-2024-46679CVE-2024-46685CVE-2024-46689CVE-2024-46714CVE-2024-46719CVE-2024-46721CVE-2024-46722CVE-2024-46723CVE-2024-46737CVE-2024-46738CVE-2024-46739CVE-2024-46740CVE-2024-46743CVE-2024-46744CVE-2024-46745CVE-2024-46747CVE-2024-46750CVE-2024-46755CVE-2024-46756CVE-2024-46757CVE-2024-46758CVE-2024-46759CVE-2024-46761CVE-2024-46771CVE-2024-46777CVE-2024-46780CVE-2024-46781CVE-2024-46782CVE-2024-46783CVE-2024-46798CVE-2024-46800CVE-2024-46815CVE-2024-46817CVE-2024-46818CVE-2024-46822CVE-2024-46828CVE-2024-46829CVE-2024-46840CVE-2024-46844CVE-2024-47659CVE-2024-47663CVE-2024-47667CVE-2024-47668CVE-2024-47669

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
Upstream advisory

USN-7068-1

USNActive exploitation (sightings)HIGH2024-10-15

imagemagick vulnerabilities

CVEs:CVE-2019-7397CVE-2019-7398CVE-2019-9956CVE-2020-19667CVE-2020-25664CVE-2020-25665CVE-2020-25666CVE-2020-25674CVE-2020-25676CVE-2020-27560CVE-2020-27750CVE-2020-27753CVE-2020-27754CVE-2020-27755CVE-2020-27758CVE-2020-27759CVE-2020-27760CVE-2020-27761CVE-2020-27762CVE-2020-27763CVE-2020-27764CVE-2020-27765CVE-2020-27766CVE-2020-27767CVE-2020-27768CVE-2020-27769CVE-2020-27770CVE-2020-27771CVE-2020-27772CVE-2020-27773CVE-2020-27774CVE-2020-27775CVE-2020-27776

Affected products

ProductStatusVendorPackageEcosystem
imagemagick affected Ubuntu:Pro:14.04:LTS imagemagick
imagemagick affected Ubuntu:Pro:16.04:LTS imagemagick
Upstream advisory

USN-7053-1

USNActive exploitation (sightings)HIGH2024-10-03

imagemagick vulnerabilities

CVEs:CVE-2019-7175CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-19948CVE-2019-19949

Affected products

ProductStatusVendorPackageEcosystem
imagemagick affected Ubuntu:Pro:14.04:LTS imagemagick
Upstream advisory

USN-7070-1

USNActive exploitation (sightings)HIGH2024-10-16

libarchive vulnerabilities

CVEs:CVE-2022-36227CVE-2024-48957CVE-2024-48958

Affected products

ProductStatusVendorPackageEcosystem
libarchive affected Ubuntu:Pro:14.04:LTS libarchive
libarchive affected Ubuntu:Pro:16.04:LTS libarchive
libarchive affected Ubuntu:22.04:LTS libarchive
libarchive affected Ubuntu:24.04:LTS libarchive
libarchive affected Ubuntu:20.04:LTS libarchive
libarchive affected Ubuntu:Pro:18.04:LTS libarchive
Upstream advisory

USN-7062-1

USNActive exploitation (sightings)HIGH2024-10-10

libgsf vulnerabilities

CVEs:CVE-2024-36474CVE-2024-42415

Affected products

ProductStatusVendorPackageEcosystem
libgsf affected Ubuntu:24.04:LTS libgsf
libgsf affected Ubuntu:22.04:LTS libgsf
libgsf affected Ubuntu:20.04:LTS libgsf
Upstream advisory

USN-7059-2

USNActive exploitation (sightings)2024-10-17

oath-toolkit vulnerability

CVEs:CVE-2024-47191

Affected products

ProductStatusVendorPackageEcosystem
oath-toolkit affected Ubuntu:24.10 oath-toolkit
Upstream advisory

USN-7059-1

USNActive exploitation (sightings)CRITICAL2024-10-09

oath-toolkit vulnerability

CVEs:CVE-2024-47191

Affected products

ProductStatusVendorPackageEcosystem
oath-toolkit affected Ubuntu:24.04:LTS oath-toolkit
oath-toolkit affected Ubuntu:22.04:LTS oath-toolkit
Upstream advisory

USN-7014-3

USNActive exploitation (sightings)HIGH2024-10-14

nginx vulnerability

CVEs:CVE-2024-7347

Affected products

ProductStatusVendorPackageEcosystem
nginx affected Ubuntu:Pro:14.04:LTS nginx
nginx affected Ubuntu
Upstream advisory

USN-7014-2

USNActive exploitation (sightings)HIGH2024-10-08

nginx vulnerability

CVEs:CVE-2024-7347

Affected products

ProductStatusVendorPackageEcosystem
nginx affected nginx
nginx affected Ubuntu:Pro:18.04:LTS nginx
nginx affected Ubuntu:Pro:16.04:LTS nginx
Upstream advisory

USN-7078-1

USNActive exploitation (sightings)CRITICAL2024-10-22

firefox vulnerability

CVEs:CVE-2024-9936

Affected products

ProductStatusVendorPackageEcosystem
firefox affected Ubuntu:20.04:LTS firefox
Upstream advisory

USN-7055-1

USNPoC exploitHIGH2024-10-03

freeradius vulnerability

CVEs:CVE-2024-3596

Affected products

ProductStatusVendorPackageEcosystem
freeradius affected Ubuntu:22.04:LTS freeradius
freeradius affected Ubuntu:20.04:LTS freeradius
freeradius affected Ubuntu:24.04:LTS freeradius
Upstream advisory

USN-7087-1

USNPoC exploitHIGH2024-10-31

libarchive vulnerability

CVEs:CVE-2024-20696

Affected products

ProductStatusVendorPackageEcosystem
libarchive affected Ubuntu:22.04:LTS libarchive
libarchive affected Ubuntu:24.04:LTS libarchive
libarchive affected Ubuntu:20.04:LTS libarchive
Upstream advisory

USN-7015-4

USNPoC exploitCRITICAL2024-10-14

python2.7, python3.5 vulnerability

CVEs:CVE-2023-27043

Affected products

ProductStatusVendorPackageEcosystem
python2.7 affected Ubuntu
python2.7 affected Ubuntu:Pro:14.04:LTS python2.7
python3.5 affected Ubuntu:Pro:14.04:LTS python3.5
Upstream advisory

USN-7015-3

USNPoC exploitCRITICAL2024-10-01

python2.7, python3.5 vulnerability

CVEs:CVE-2023-27043

Affected products

ProductStatusVendorPackageEcosystem
python2.7 affected Ubuntu:Pro:22.04:LTS python2.7
python2.7 affected Ubuntu:Pro:16.04:LTS python2.7
python2.7 affected Ubuntu
python2.7 affected Ubuntu:Pro:20.04:LTS python2.7
python2.7 affected Ubuntu:Pro:18.04:LTS python2.7
python3.5 affected Ubuntu:Pro:16.04:LTS python3.5
Upstream advisory

USN-6968-3

USNPoC exploit2024-10-14

postgresql-10, postgresql-9.3 vulnerability

CVEs:CVE-2024-7348

Affected products

ProductStatusVendorPackageEcosystem
postgresql-10 affected Ubuntu:Pro:18.04:LTS postgresql-10
postgresql-9.3 affected Ubuntu:Pro:14.04:LTS postgresql-9.3
Upstream advisory

USN-7040-2

USNPoC exploitHIGH2024-10-14

configobj vulnerability

CVEs:CVE-2023-26112

Affected products

ProductStatusVendorPackageEcosystem
configobj affected Ubuntu:Pro:14.04:LTS configobj
Upstream advisory

USN-7084-2

USNPoC exploitHIGH2024-10-30

python-pip vulnerability

CVEs:CVE-2024-37891

Affected products

ProductStatusVendorPackageEcosystem
python-pip affected Ubuntu:Pro:18.04:LTS python-pip
python-pip affected Ubuntu:20.04:LTS python-pip
python-pip affected Ubuntu:24.04:LTS python-pip
python-pip affected Ubuntu:Pro:16.04:LTS python-pip
python-pip affected Ubuntu:22.04:LTS python-pip
Upstream advisory

USN-7084-1

USNPoC exploitHIGH2024-10-29

python-urllib3 vulnerability

CVEs:CVE-2024-37891

Affected products

ProductStatusVendorPackageEcosystem
python-urllib3 affected Ubuntu:Pro:16.04:LTS python-urllib3
python-urllib3 affected Ubuntu:24.04:LTS python-urllib3
python-urllib3 affected Ubuntu:20.04:LTS python-urllib3
python-urllib3 affected Ubuntu:Pro:18.04:LTS python-urllib3
python-urllib3 affected Ubuntu:22.04:LTS python-urllib3
Upstream advisory

USN-7049-1

USNPoC exploitCRITICAL2024-10-01

php7.4, php8.1, php8.3 vulnerabilities

CVEs:CVE-2024-8925CVE-2024-8927CVE-2024-9026

Affected products

ProductStatusVendorPackageEcosystem
php7.4 affected Ubuntu:20.04:LTS php7.4
php8.1 affected Ubuntu:22.04:LTS php8.1
php8.3 affected Ubuntu:24.04:LTS php8.3
Upstream advisory

USN-7079-1

USNPoC exploitHIGH2024-10-22

webkit2gtk vulnerabilities

CVEs:CVE-2024-40866CVE-2024-44187

Affected products

ProductStatusVendorPackageEcosystem
webkit2gtk affected Ubuntu:24.04:LTS webkit2gtk
webkit2gtk affected Ubuntu:22.04:LTS webkit2gtk
Upstream advisory

USN-7050-1

USNPoC exploitCRITICAL2024-10-01

ruby-devise-two-factor vulnerabilities

CVEs:CVE-2021-43177CVE-2024-8796

Affected products

ProductStatusVendorPackageEcosystem
ruby-devise-two-factor affected Ubuntu:Pro:22.04:LTS ruby-devise-two-factor
ruby-devise-two-factor affected Ubuntu:Pro:20.04:LTS ruby-devise-two-factor
Upstream advisory

USN-7003-5

USNPoC exploitMEDIUM2024-10-01

linux-raspi-5.4 vulnerabilities

CVEs:CVE-2023-52803CVE-2023-52887CVE-2024-36894CVE-2024-36974CVE-2024-36978CVE-2024-37078CVE-2024-38619CVE-2024-39469CVE-2024-39487CVE-2024-39495CVE-2024-39499CVE-2024-39501CVE-2024-39502CVE-2024-39503CVE-2024-39505CVE-2024-39506CVE-2024-39509CVE-2024-40901CVE-2024-40902CVE-2024-40904CVE-2024-40905CVE-2024-40912CVE-2024-40916CVE-2024-40932CVE-2024-40934CVE-2024-40941CVE-2024-40942CVE-2024-40943CVE-2024-40945CVE-2024-40958CVE-2024-40959CVE-2024-40960CVE-2024-40961CVE-2024-40963CVE-2024-40968CVE-2024-40974CVE-2024-40978CVE-2024-40980CVE-2024-40981CVE-2024-40984CVE-2024-40987CVE-2024-40988CVE-2024-40995CVE-2024-41006CVE-2024-41007CVE-2024-41034CVE-2024-41035CVE-2024-41041CVE-2024-41044CVE-2024-41046CVE-2024-41049CVE-2024-41087CVE-2024-41089CVE-2024-41095CVE-2024-41097CVE-2024-42070CVE-2024-42076CVE-2024-42084CVE-2024-42086CVE-2024-42087CVE-2024-42089CVE-2024-42090CVE-2024-42092CVE-2024-42093CVE-2024-42094CVE-2024-42096CVE-2024-42097CVE-2024-42101CVE-2024-42102CVE-2024-42104CVE-2024-42105CVE-2024-42106CVE-2024-42115CVE-2024-42119CVE-2024-42124CVE-2024-42127CVE-2024-42145CVE-2024-42148CVE-2024-42153CVE-2024-42154CVE-2024-42157CVE-2024-42223CVE-2024-42224CVE-2024-42232CVE-2024-42236

Affected products

ProductStatusVendorPackageEcosystem
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4
Upstream advisory

USN-7028-2

USNPoC exploitMEDIUM2024-10-17

linux-azure vulnerabilities

CVEs:CVE-2021-47188CVE-2022-48791CVE-2022-48863CVE-2023-52527CVE-2023-52809CVE-2024-26651CVE-2024-26677CVE-2024-26733CVE-2024-26851CVE-2024-26880CVE-2024-26984CVE-2024-27398CVE-2024-27437CVE-2024-38570CVE-2024-38583CVE-2024-39480CVE-2024-39495CVE-2024-40902CVE-2024-42154CVE-2024-42160CVE-2024-42224CVE-2024-42228

Affected products

ProductStatusVendorPackageEcosystem
linux-azure affected Ubuntu
linux-azure affected Ubuntu:Pro:14.04:LTS linux-azure
Upstream advisory

USN-7077-1

USNPoC exploitHIGH2024-10-21

amd64-microcode vulnerability

CVEs:CVE-2023-31315

Affected products

ProductStatusVendorPackageEcosystem
amd64-microcode affected Ubuntu:Pro:16.04:LTS amd64-microcode
amd64-microcode affected Ubuntu:Pro:18.04:LTS amd64-microcode
amd64-microcode affected Ubuntu:22.04:LTS amd64-microcode
amd64-microcode affected Ubuntu:20.04:LTS amd64-microcode
amd64-microcode affected Ubuntu:24.04:LTS amd64-microcode
Upstream advisory

USN-7064-1

USNPoC exploitCRITICAL2024-10-15

nano vulnerability

CVEs:CVE-2024-5742

Affected products

ProductStatusVendorPackageEcosystem
nano affected Ubuntu:20.04:LTS nano
nano affected Ubuntu:24.04:LTS nano
nano affected Ubuntu:Pro:16.04:LTS nano
nano affected Ubuntu:Pro:18.04:LTS nano
nano affected Ubuntu:22.04:LTS nano
Upstream advisory

USN-7073-1

USNPoC exploitNONE2024-10-16

linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities

CVEs:CVE-2024-26960CVE-2024-27397CVE-2024-38630CVE-2024-45016

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:20.04:LTS linux
linux-aws affected Ubuntu:20.04:LTS linux-aws
linux-aws-5.4 affected Ubuntu:Pro:18.04:LTS linux-aws-5.4
linux-bluefield affected Ubuntu:20.04:LTS linux-bluefield
linux-gcp affected Ubuntu:20.04:LTS linux-gcp
linux-gcp-5.4 affected Ubuntu:Pro:18.04:LTS linux-gcp-5.4
linux-gkeop affected Ubuntu:20.04:LTS linux-gkeop
linux-hwe-5.4 affected Ubuntu:Pro:18.04:LTS linux-hwe-5.4
linux-ibm affected Ubuntu:20.04:LTS linux-ibm
linux-ibm-5.4 affected Ubuntu:Pro:18.04:LTS linux-ibm-5.4
linux-kvm affected Ubuntu:20.04:LTS linux-kvm
linux-oracle affected Ubuntu:20.04:LTS linux-oracle
linux-oracle-5.4 affected Ubuntu:Pro:18.04:LTS linux-oracle-5.4
linux-raspi affected Ubuntu:20.04:LTS linux-raspi
linux-raspi-5.4 affected Ubuntu:Pro:18.04:LTS linux-raspi-5.4
linux-xilinx-zynqmp affected Ubuntu:20.04:LTS linux-xilinx-zynqmp
Upstream advisory

USN-7072-1

USNPoC exploitNONE2024-10-16

linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi, linux-xilinx-zynqmp vulnerabilities

CVEs:CVE-2024-27397CVE-2024-38630CVE-2024-45016

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:22.04:LTS linux
linux-aws affected Ubuntu:22.04:LTS linux-aws
linux-aws-5.15 affected Ubuntu:20.04:LTS linux-aws-5.15
linux-gcp affected Ubuntu:22.04:LTS linux-gcp
linux-gcp-5.15 affected Ubuntu:20.04:LTS linux-gcp-5.15
linux-gkeop affected Ubuntu:22.04:LTS linux-gkeop
linux-gkeop-5.15 affected Ubuntu:20.04:LTS linux-gkeop-5.15
linux-hwe-5.15 affected Ubuntu:20.04:LTS linux-hwe-5.15
linux-ibm affected Ubuntu:22.04:LTS linux-ibm
linux-ibm-5.15 affected Ubuntu:20.04:LTS linux-ibm-5.15
linux-intel-iotg affected Ubuntu:22.04:LTS linux-intel-iotg
linux-intel-iotg-5.15 affected Ubuntu:20.04:LTS linux-intel-iotg-5.15
linux-kvm affected Ubuntu:22.04:LTS linux-kvm
linux-lowlatency affected Ubuntu:22.04:LTS linux-lowlatency
linux-lowlatency-hwe-5.15 affected Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15
linux-nvidia affected Ubuntu:22.04:LTS linux-nvidia
linux-oracle affected Ubuntu:22.04:LTS linux-oracle
linux-oracle-5.15 affected Ubuntu:20.04:LTS linux-oracle-5.15
linux-raspi affected Ubuntu:22.04:LTS linux-raspi
linux-xilinx-zynqmp affected Ubuntu:22.04:LTS linux-xilinx-zynqmp
Upstream advisory

USN-7071-1

USNPoC exploitNONE2024-10-16

linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-hwe-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oem-6.8, linux-oracle, linux-oracle-6.8, linux-raspi vulnerability

CVEs:CVE-2024-45016

Affected products

ProductStatusVendorPackageEcosystem
linux affected Ubuntu:24.04:LTS linux
linux-aws affected Ubuntu:24.04:LTS linux-aws
linux-aws-6.8 affected Ubuntu:22.04:LTS linux-aws-6.8
linux-gcp affected Ubuntu:24.04:LTS linux-gcp
linux-gcp-6.8 affected Ubuntu:22.04:LTS linux-gcp-6.8
linux-hwe-6.8 affected Ubuntu:22.04:LTS linux-hwe-6.8
linux-ibm affected Ubuntu:24.04:LTS linux-ibm
linux-lowlatency affected Ubuntu:24.04:LTS linux-lowlatency
linux-lowlatency-hwe-6.8 affected Ubuntu:22.04:LTS linux-lowlatency-hwe-6.8
linux-nvidia affected Ubuntu:24.04:LTS linux-nvidia
linux-nvidia-6.8 affected Ubuntu:22.04:LTS linux-nvidia-6.8
linux-nvidia-lowlatency affected Ubuntu:24.04:LTS linux-nvidia-lowlatency
linux-oem-6.8 affected Ubuntu:24.04:LTS linux-oem-6.8
linux-oracle affected Ubuntu:24.04:LTS linux-oracle
linux-oracle-6.8 affected Ubuntu:22.04:LTS linux-oracle-6.8
linux-raspi affected Ubuntu:24.04:LTS linux-raspi
Upstream advisory

USN-7057-2

USNPoC exploitNONE2024-10-08

ruby-webrick vulnerability

CVEs:CVE-2024-47220

Affected products

ProductStatusVendorPackageEcosystem
ruby-webrick affected Ubuntu:22.04:LTS ruby-webrick
Upstream advisory

USN-7057-1

USNPoC exploitNONE2024-10-07

ruby-webrick vulnerability

CVEs:CVE-2024-47220

Affected products

ProductStatusVendorPackageEcosystem
ruby-webrick affected Ubuntu:24.04:LTS ruby-webrick
Upstream advisory

USN-7085-2

USNCoalition ESS < 30%CRITICAL2024-10-30

xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerability

CVEs:CVE-2024-9632

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:Pro:16.04:LTS xorg-server
xorg-server affected Ubuntu:Pro:18.04:LTS xorg-server
xorg-server-hwe-16.04 affected Ubuntu:Pro:16.04:LTS xorg-server-hwe-16.04
xorg-server-hwe-18.04 affected Ubuntu:Pro:18.04:LTS xorg-server-hwe-18.04
Upstream advisory

USN-7085-1

USNCoalition ESS < 30%CRITICAL2024-10-30

xorg-server, xwayland vulnerability

CVEs:CVE-2024-9632

Affected products

ProductStatusVendorPackageEcosystem
xorg-server affected Ubuntu:22.04:LTS xorg-server
xorg-server affected Ubuntu:24.04:LTS xorg-server
xorg-server affected Ubuntu:20.04:LTS xorg-server
xwayland affected Ubuntu:22.04:LTS xwayland
xwayland affected Ubuntu:24.04:LTS xwayland
Upstream advisory

USN-7082-1

USNCoalition ESS < 30%HIGH2024-10-23

libheif vulnerability

CVEs:CVE-2024-41311

Affected products

ProductStatusVendorPackageEcosystem
libheif affected Ubuntu:24.04:LTS libheif
Upstream advisory

USN-7080-1

USNCoalition ESS < 30%HIGH2024-10-22

unbound vulnerability

CVEs:CVE-2024-8508

Affected products

ProductStatusVendorPackageEcosystem
unbound affected Ubuntu:24.04:LTS unbound
unbound affected Ubuntu:20.04:LTS unbound
unbound affected Ubuntu:Pro:18.04:LTS unbound
unbound affected Ubuntu:Pro:16.04:LTS unbound
unbound affected Ubuntu:22.04:LTS unbound
unbound affected Ubuntu:Pro:14.04:LTS unbound
Upstream advisory

USN-6964-2

USNCoalition ESS < 30%CRITICAL2024-10-01

orc vulnerability

CVEs:CVE-2024-40897

Affected products

ProductStatusVendorPackageEcosystem
orc affected Ubuntu:Pro:18.04:LTS orc
orc affected Ubuntu:Pro:16.04:LTS orc
Upstream advisory

USN-7048-1

USNCoalition ESS < 30%HIGH2024-10-01

vim vulnerability

CVEs:CVE-2024-43802

Affected products

ProductStatusVendorPackageEcosystem
vim affected Ubuntu:Pro:18.04:LTS vim
vim affected Ubuntu:24.04:LTS vim
vim affected Ubuntu:20.04:LTS vim
vim affected Ubuntu:Pro:16.04:LTS vim
vim affected Ubuntu:22.04:LTS vim
Upstream advisory

USN-7063-1

USNCoalition ESS < 30%NONE2024-10-11

ubuntu-advantage-desktop-daemon vulnerability

CVEs:CVE-2024-6388

Affected products

ProductStatusVendorPackageEcosystem
ubuntu-advantage-desktop-daemon affected Ubuntu:22.04:LTS ubuntu-advantage-desktop-daemon
ubuntu-advantage-desktop-daemon affected Ubuntu:Pro:16.04:LTS ubuntu-advantage-desktop-daemon
ubuntu-advantage-desktop-daemon affected Ubuntu:20.04:LTS ubuntu-advantage-desktop-daemon
ubuntu-advantage-desktop-daemon affected Ubuntu:Pro:18.04:LTS ubuntu-advantage-desktop-daemon
ubuntu-advantage-desktop-daemon affected Ubuntu:24.04:LTS ubuntu-advantage-desktop-daemon
Upstream advisory

UBUNTU-CVE-2019-25219

USNEPSS <= 49%HIGH2024-10-29

CVEs:CVE-2019-25219

Affected products

ProductStatusVendorPackageEcosystem
asio affected Ubuntu:18.04:LTS asio
asio affected Ubuntu:16.04:LTS asio
asio affected Ubuntu:20.04:LTS asio
Upstream advisory

USN-7042-2

USNAll remaining2024-10-09

cups-browsed vulnerability

Affected products

ProductStatusVendorPackageEcosystem
cups-browsed affected Ubuntu:24.04:LTS cups-browsed
Upstream advisory

USN-7058-1

USNAll remaining2024-10-08

dotnet6, dotnet8 vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
dotnet6 affected Ubuntu:22.04:LTS dotnet6
dotnet8 affected Ubuntu:22.04:LTS dotnet8
dotnet8 affected Ubuntu:24.04:LTS dotnet8
Upstream advisory

USN-7054-1

USNAll remaining2024-10-03

unzip vulnerability

Affected products

ProductStatusVendorPackageEcosystem
unzip affected Ubuntu:24.04:LTS unzip
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.