CVE reports

The Common Vulnerabilities and Exposures (CVE) system is used to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Canonical keeps track of all CVEs affecting Ubuntu, and releases a security notice when an issue is fixed. You can find additional guidance for high-profile vulnerabilities in the Ubuntu Vulnerability Knowledge Base section


Search CVEs


Recent CVEs

CVE-2026-1584

High priority
Not affected

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can...

1 affected package

gnutls28


CVE-2026-35535

High priority
Fixed

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

1 affected package

sudo


CVE-2026-23410

High priority

Some fixes available 94 of 142

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an...

157 affected packages

linux-kvm, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...


CVE-2026-23411

High priority

Some fixes available 94 of 142

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from...

157 affected packages

linux-azure-4.15, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...


CVE-2018-25223

High priority
Needs evaluation

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code...

1 affected package

crashmail