Vulnerability knowledge base
Applying security updates in a timely manner is critical to reducing risks, especially with high-impact vulnerabilities. Canonical releases Ubuntu Security Notices whenever a security fix is available for an official Ubuntu package.
When high-profile vulnerabilities are publicly disclosed, the Ubuntu security team also provides in-depth technical explanations and mitigation guidance in the form of vulnerability knowledge base articles.
Recent vulnerabilities
2024
A new variant of the previously-disclosed BHI (also known as Spectre v2) vulnerabilities was discovered to affected certain Intel CPUs. The new publication shows that attacks are possible using vectors other than eBPF, leading to...
2023
It was discovered that some Intel processors were vulnerable to information exposure in certain vector (AVX) operations.
2022
Multiple issues were discovered in AMD and Intel CPUs that result in information disclosure under mitigations for the Spectre Variant 2 vulnerability.
It was discovered that readable files could be overwritten at the page cache level unintentionally or by a malicious actor. That includes files that the process did not have write access to, were immutable or were on read-only filesystems.
It was discovered that CPU internals can be abused by an unprivileged process to lead to information disclosure.
Resources
Ubuntu security updates
Ubuntu Pro
Up to 12 years of security coverage for Ubuntu and 36,000 open-source applications and toolchains.