---
title: "Vulnerability Knowledge Base\n    | Ubuntu"
description: A library with in-depth information and technical guidance for high-impact
  vulnerabilities that affect Ubuntu.
url: https://ubuntu.com/security/vulnerabilities/view-all?format=md
keywords: index, follow
---

1. [Vulnerability knowledge base](https://ubuntu.com/security/vulnerabilities)
2. View all

---

# Vulnerability knowledge base

Open side navigation

2026

---

### [EntrySign - AMD Zen microcode signature verification vulnerability (CVE-2024-36347, CVE-2024-56161)](https://ubuntu.com/security/vulnerabilities/entrysign)

Guidance available

Published 6 April 2026

It was discovered that some AMD Zen processors did not properly verify the signature of CPU microcode which could lead to the loss of integrity and confidentiality if a malicious CPU microcode is loaded.

Published 6 April 2026

---

### [AppArmor security vulnerabilities (CrackArmor)](https://ubuntu.com/security/vulnerabilities/crackarmor)

Fixed

Published 12 March 2026

Several vulnerabilities were discovered in AppArmor which could lead to denial of service, kernel memory information leak, removing security controls, or local privilege escalation to root user.

Published 12 March 2026

2025

---

### [VMSCAPE BPI (Branch Predictor Isolation) in KVM (CVE-2025-40300)](https://ubuntu.com/security/vulnerabilities/vmscape)

Fixed

Published 12 September 2025

Issues were discovered in AMD, Intel, and Hygon CPUs that result in information disclosure to KVM virtual machine guests under mitigations for the Spectre Variant 2 vulnerability.

Published 12 September 2025

2024

---

### [Native BHI (Branch History Injection 2) (CVE-2024-2201)](https://ubuntu.com/security/vulnerabilities/native-bhi)

Fixed

Published 24 April 2024

A new variant of the previously-disclosed BHI (also known as Spectre v2) vulnerabilities was discovered to affected certain Intel CPUs. The new publication shows that attacks are possible using vectors other than eBPF, leading to...

Published 24 April 2024

2023

---

### [Gather Data Sampling (GDS) Downfall (CVE-2022-40982)](https://ubuntu.com/security/vulnerabilities/gds-downfall)

Fixed

Published 24 August 2023

It was discovered that some Intel processors were vulnerable to information exposure in certain vector (AVX) operations.

Published 24 August 2023

2022

---

### [Retbleed and related return predictor microarchitectural flaws (CVE-2022-29901, CVE-2022-28693, CVE-2022-23816, CVE-2022-23825)](https://ubuntu.com/security/vulnerabilities/retbleed)

Fixed

Published 12 July 2022

Multiple issues were discovered in AMD and Intel CPUs that result in information disclosure under mitigations for the Spectre Variant 2 vulnerability.

Published 12 July 2022

---

### [Dirty Pipe – page cache overwrite with pipes flaw in the Linux Kernel (CVE-2022-0847)](https://ubuntu.com/security/vulnerabilities/dirtypipe)

Fixed

Published 10 March 2022

It was discovered that readable files could be overwritten at the page cache level unintentionally or by a malicious actor. That includes files that the process did not have write access to, were immutable or were on read-only filesystems.

Published 10 March 2022

---

### [Branch History Injection Microarchitectural flaws (CVE-2022-0001, CVE-2022-0002, CVE-2022-23960)](https://ubuntu.com/security/vulnerabilities/bhi)

Fixed

Published 8 March 2022

It was discovered that CPU internals can be abused by an unprivileged process to lead to information disclosure.

Published 8 March 2022

2021

---

### [Log4Shell – Apache Log4j 2 remote code execution (CVE-2021-44228)](https://ubuntu.com/security/vulnerabilities/log4shell)

Fixed

Published 9 December 2021

A zero-day vulnerability was discovered in Apache Log4j 2, a Java logging framework, that allows for arbitrary code execution through the exploitation of requests to attacker-controlled LDAP and other JNDI endpoints.

Published 9 December 2021

---

### [GRUB2 Secure Boot Bypass (CVE-2020-14372, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233, CVE-2021-3418)](https://ubuntu.com/security/vulnerabilities/grub-secure-boot-bypass)

Fixed

Published 2 March 2021

Several vulnerabilities have been identified in GRUB2 that allow UEFI Secure Boot protections to be bypassed by a local attacker with administrative privileges (root) or physical access. These are different from the previously...

Published 2 March 2021

2020

---

### [Platypus – Intel power side-channels (CVE-2020-8694, CVE-2020-8695)](https://ubuntu.com/security/vulnerabilities/platypus)

Fixed

Published 10 November 2020

Several vulnerabilities have been identified that affect the Linux kernel on Intel hosts through power side-channel attacks that allow information to be disclosed to non-privileged processes.

Published 10 November 2020

---

### [BootHole – GRUB2 Secure Boot Bypass (CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707)](https://ubuntu.com/security/vulnerabilities/boothole)

Fixed

Published 29 July 2020

Several vulnerabilities have been identified in GRUB2 that allow UEFI Secure Boot protections to be bypassed by a local attacker with administrative privileges (root) or physical access.

Published 29 July 2020

---

### [Crosstalk – Special Register Buffer Data Sampling (SRBDS) hardware vulnerability in Intel CPUs (CVE-2020-0543)](https://ubuntu.com/security/vulnerabilities/crosstalk)

Fixed

Published 9 June 2020

A vulnerability was discovered affecting selected Intel CPUs that could allow a local attacker to expose the memory of processes running on the same CPU as the malicious code.

Published 9 June 2020

2019

---

### [TSX Asynchronous Abort (TAA) (CVE-2019-11135), Intel® Processor Machine Check Error (MCEPSC) (CVE-2018-12207), and i915 graphics (CVE-2019-0155, CVE-2019-0154) vulnerabilities](https://ubuntu.com/security/vulnerabilities/taa-mcepsc-i915)

Fixed

Published 12 November 2019

Several vulnerabilities have been identified in Intel CPUs and graphics cards that allow a local attacker to expose memory across security boundaries (similar to MDS), cause Denial of Service attacks, or escalate privileges.

Published 12 November 2019

---

### [HTTP/2 Denial of Service vulnerabilities](https://ubuntu.com/security/vulnerabilities/http-2-dos)

Fixed

Published 13 August 2019

Several vulnerabilities were discovered in multiple implementations of the HTTP/2 transport protocol that allow a remote attacker to mount Denial of Service attacks.

Published 13 August 2019

---

### [Kubernetes API server vulnerability (CVE-2019-11247)](https://ubuntu.com/security/vulnerabilities/k8s-cve-2019-11247)

Fixed

Published 5 August 2019

A Kubernetes vulnerability has been identified where the API server mistakenly allows access to a cluster-scoped custom resource, when the requesting user has restricted access to namespaced resources.

Published 5 August 2019

---

### [SACK Panic and other TCP Denial of Service issues (CVE-2019-11477, CVE-2019-11478, CVE-2019-11479)](https://ubuntu.com/security/vulnerabilities/sack-panic)

Fixed

Published 17 June 2019

Several vulnerabilities were discovered in the Linux kernel’s implementation of TCP that allow a remote attacker to cause a Denial of Service attack.

Published 17 June 2019

---

### [Microarchitectural Data Sampling (MDS) (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091)](https://ubuntu.com/security/vulnerabilities/mds)

Fixed

Published 14 May 2019

A vulnerability was discovered in Intel CPUs that allow a local attacker to access data belonging to another process or data that originated from a different security context. As a result, unintended memory exposure can occur...

Published 14 May 2019

---

### [Snap Socket Parsing (CVE-2019-7304)](https://ubuntu.com/security/vulnerabilities/snap-socket-parsing)

Fixed

Published 12 February 2019

A vulnerability was discovered in snapd that allow local privilege escalation attacks to be executed.

Published 12 February 2019

---

### [{'text': 'runC / docker.io privileged container escape (CVE-2019-5736)', 'url': 'http://docker.io'}](https://ubuntu.com/security/vulnerabilities/runc)

Fixed

Published 11 February 2019

It was discovered that a vulnerability affecting the runC container runtime can allow an attacker to gain root privileges on the host from inside a privileged container.

Published 11 February 2019

2018

---

### [L1 Terminal Fault (L1TF) (CVE-2018-3615, CVE-2018-3620, CVE-2018-3646)](https://ubuntu.com/security/vulnerabilities/l1tf)

Fixed

Published 14 August 2018

A vulnerability was discovered that allows a local attacker to extract memory associated to other processes from the L1 cache.

Published 14 August 2018

---

### [NetSpectre](https://ubuntu.com/security/vulnerabilities/netspectre)

Guidance available

Published 27 July 2018

A side channel attack was discovered against applications previously assumed to be immune to the Spectre vulnerability that can be used to read the contents of memory across a network.

Published 27 July 2018

---

### [Bounds Check Bypass Store (BCBS) – Spectre 1.1, Spectre 1.2 (CVE-2018-3693)](https://ubuntu.com/security/vulnerabilities/bcbs)

Guidance available

Published 10 July 2018

It was discovered that systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and...

Published 10 July 2018

---

### [Lazy FP Save/Restore (CVE-2018-3665)](https://ubuntu.com/security/vulnerabilities/lazyfp)

Fixed

Published 13 June 2018

A side channel attack was discovered that leaks certain register values between processes.

Published 13 June 2018

---

### [GPZ Variant 4 of Side Channel issues (CVE-2018-3639)](https://ubuntu.com/security/vulnerabilities/gpz-variant-4)

Fixed

Published 21 May 2018

A variant of a cache speculation timing side channel attack was discovered, similar to the issues previously disclosed under the names Spectre and Meltdown.

Published 21 May 2018

---

### [Mov/Pop SS vulnerabilities (CVE-2018-8897, CVE-2018-1087)](https://ubuntu.com/security/vulnerabilities/pop-ss)

Fixed

Published 8 May 2018

A vulnerability was discovered in the Linux kernel that could be exploited by a local attacker to cause a denial of service (system crash). This issue only affected the amd64 architecture.

Published 8 May 2018

2017

---

### [BlueBorne – Bluetooth vulnerabilities (CVE-2017-1000250, CVE-2017-1000251)](https://ubuntu.com/security/vulnerabilities/blueborne)

Fixed

Published 12 September 2017

Two issues were discovered affecting the Bluetooth subsystem: an information disclosure in the BlueZ daemon and a kernel stack-based buffer overflow that can cause denial of service through a system crash, both of which a...

Published 12 September 2017

---

### [Spectre and Meltdown vulnerabilities (CVE-2017-5753, CVE-2017-5754, and CVE-2017-5715)](https://ubuntu.com/security/vulnerabilities/spectre-and-meltdown)

Fixed

Published 4 January 2017

Security researchers announced a new class of side channel attacks that impact most processors, including processors from Intel, AMD, ARM and IBM. The attack allows malicious userspace processes to read kernel memory and malicious...

Published 4 January 2017

2016

---

### [httpoxy – CGI application vulnerability](https://ubuntu.com/security/vulnerabilities/httpoxy)

Fixed

Published 18 July 2016

It was discovered that certain CGI environments had a vulnerability related to the processing of the Proxy header.

Published 18 July 2016

---

### [OpenSSH Client Roaming (CVE-2016-0777, CVE-2016-0778)](https://ubuntu.com/security/vulnerabilities/openssh-client-roaming)

Fixed

Published 14 January 2016

Two vulnerabilities were discovered in the OpenSSH client that could be exploited by a malicious SSH server to disclose private data (including private keys) or overwrite certain areas of the client’s memory.

Published 14 January 2016

2015

---

### [Stagefright (CVE-2015-1538, CVE-2015-1539, CVE-2015-3824, CVE-2015-3826, CVE-2015-3827, CVE-2015-3828, CVE-2015-3829)](https://ubuntu.com/security/vulnerabilities/stagefright)

Not affected

Published 29 July 2015

The Android stagefright vulnerability allows for a remote attacker to send a crafted MMS message to a victim’s phone to steal data, access hardware and install malware. Ubuntu Touch does not expose the affected functionality of...

Published 29 July 2015

---

### [LogJam (CVE-2015-4000)](https://ubuntu.com/security/vulnerabilities/logjam)

Fixed

Published 21 May 2015

Cryptanalysis has shown that the use of shared parameters and short key sizes makes Diffie-Hellman exchange subceptible to compromise.

Published 21 May 2015

---

### [VENOM (CVE-2015-3456)](https://ubuntu.com/security/vulnerabilities/venom)

Fixed

Published 13 May 2015

It was discovered that a buffer overflow existed in the virtual floppy disk controller of QEMU. An attacker could use this issue to cause QEMU to crash or execute arbitrary code in the host’s QEMU process.

Published 13 May 2015

---

### [GHOST (CVE-2015-0235)](https://ubuntu.com/security/vulnerabilities/ghost)

Fixed

Published 27 January 2015

It was discovered that a buffer overflow existed in a GNU C Library function. An attacker could use this issue to execute arbitrary code or cause an application crash, resulting in a denial of service.

Published 27 January 2015

[Back to top](https://ubuntu.com/security/vulnerabilities/view-all?format=md)
