Canonical Vulnerabilities and Affected Products
Vulnerabilities associated with Ubuntu Linux.
Products
Clear product- LXD30 vulnerabilities
- apport28 vulnerabilities
- Ubuntu Linux13 vulnerabilities
- Juju12 vulnerabilities
- snapd9 vulnerabilities
- Ubuntu 22.04 LTS8 vulnerabilities
- Ubuntu 24.04 LTS8 vulnerabilities
- Ubuntu 20.04 LTS7 vulnerabilities
- Ubuntu 26.04 LTS7 vulnerabilities
- Ubuntu 16.04 LTS6 vulnerabilities
- Ubuntu 18.04 LTS6 vulnerabilities
- ubuntu_linux6 vulnerabilities
- Multipass5 vulnerabilities
- Python-apt4 vulnerabilities
- aptdaemon3 vulnerabilities
- cloud-init3 vulnerabilities
- pulseaudio3 vulnerabilities
- Ubuntu3 vulnerabilities
- ubuntu-pro-client (ubuntu-advantage-tools)3 vulnerabilities
- authd2 vulnerabilities
- Subiquity2 vulnerabilities
- ubantu_kernel2 vulnerabilities
- Ubuntu 14.04 LTS2 vulnerabilities
- Ubuntu Kernel2 vulnerabilities
- unity-firefox-extension2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediationUbuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. CWE-476May 28, 2026 | CVSS3.3v3.1 | EPSS0.094% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rulesUbuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets. CWE-457May 28, 2026 | CVSS3.3v3.1 | EPSS0.094% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-47335MEDIUM | NULL pointer dereference in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic. CWE-476May 28, 2026 | CVSS5.5v3.1 | EPSS0.097% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47334MEDIUM | Deadlock or kernel panic in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock. CWE-833May 28, 2026 | CVSS5.5v3.1 | EPSS0.078% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47333HIGH | Out-of-bounds read in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine. CWE-125May 28, 2026 | CVSS7.8v3.1 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47332MEDIUM | Out-of-bounds read in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects. CWE-125May 28, 2026 | CVSS5.5v3.1 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47331HIGH | Use-after-free in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution. CWE-416May 28, 2026 | CVSS7.8v3.1 | EPSS0.114% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Use of uninitialized value in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses. CWE-457May 28, 2026 | CVSS3.3v3.1 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Incorrect validation of field size in Ubuntu Linux AppArmor notification responsesUbuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses. CWE-1284May 28, 2026 | CVSS3.3v3.1 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-47328MEDIUM | Invalid pointer deallocation in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion. CWE-590May 28, 2026 | CVSS6.1v3.1 | EPSS0.093% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
NULL pointer dereference in Ubuntu Linux AppArmor notification handlingUbuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. CWE-476May 28, 2026 | CVSS3.3v3.1 | EPSS0.091% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-47326MEDIUM | Memory leak in Ubuntu Linux AppArmor large notification response allocationUbuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion. CWE-401May 28, 2026 | CVSS5.5v3.1 | EPSS0.093% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13350HIGH | Use-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelUbuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queue reference, so the buffer is freed while still reachable and subsequent queue walks dereference freed memory, yielding a reliable local privilege … CWE-416Mar 5, 2026 | CVSS7.1v4.0 | EPSS0.146% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |