Vulnerability knowledge base

Applying security updates in a timely manner is critical to reducing risks, especially with high-impact vulnerabilities. Canonical releases Ubuntu Security Notices whenever a security fix is available for an official Ubuntu package.

When high-profile vulnerabilities are publicly disclosed, the Ubuntu security team also provides in-depth technical explanations and mitigation guidance in the form of vulnerability knowledge base articles.


Recent vulnerabilities

2024


A new variant of the previously-disclosed BHI (also known as Spectre v2) vulnerabilities was discovered to affected certain Intel CPUs. The new publication shows that attacks are possible using vectors other than eBPF, leading to...

Published 24/04/2024

2023


It was discovered that some Intel processors were vulnerable to information exposure in certain vector (AVX) operations.

Published 24/08/2023

2022


Multiple issues were discovered in AMD and Intel CPUs that result in information disclosure under mitigations for the Spectre Variant 2 vulnerability.

Published 12/07/2022


It was discovered that readable files could be overwritten at the page cache level unintentionally or by a malicious actor. That includes files that the process did not have write access to, were immutable or were on read-only filesystems.

Published 10/03/2022


It was discovered that CPU internals can be abused by an unprivileged process to lead to information disclosure.

Published 08/03/2022


Resources


Ubuntu Pro

    Up to 12 years of security coverage for Ubuntu and 36,000 open-source applications and toolchains.