« Volver al listado

Canonical

Canonical Ubuntu Linux: vulnerabilidades y CVE

Canonical Ubuntu Linux tiene 4120 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 345 son críticas y 46 figuran en el catálogo de explotación activa de CISA.

CVE4120
Últimos 12 meses15
Críticas345
Explotadas activamente46

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-0492Alta (7.8)5.5%⚠ Explotación activa3 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to…
CVE-2026-31431Alta (7.8)3.4%⚠ Explotación activa22 abr 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…
CVE-2018-14634Alta (7.8)15%⚠ Explotación activa25 sept 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on…
CVE-2025-32463Alta (7.8)61%⚠ Explotación activa30 jun 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2023-0386Alta (7.8)7.9%⚠ Explotación activa22 mar 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid…
CVE-2016-3714Alta (8.4)97%⚠ Explotación activa5 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell…
CVE-2022-2586Alta (7.8)10%⚠ Explotación activa8 ene 2024
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVE-2023-4911Alta (7.8)81%⚠ Explotación activa3 oct 2023
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES…
CVE-2014-0196Media (5.5)22%⚠ Explotación activa7 may 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory…
CVE-2021-3560Alta (7.8)24%⚠ Explotación activa16 feb 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker…
CVE-2016-8735Crítica (9.8)90%⚠ Explotación activa6 abr 2017
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX…
CVE-2016-3427Crítica (9.8)92%⚠ Explotación activa21 abr 2016
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CVE-2010-3904Alta (7.8)14%⚠ Explotación activa6 dic 2010
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which…
CVE-2021-3493Alta (7.8)49%⚠ Explotación activa17 abr 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged…
CVE-2021-4034Alta (7.8)94%⚠ Explotación activa28 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined…
CVE-2016-1646Alta (8.8)48%⚠ Explotación activa29 mar 2016
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of…
CVE-2014-3153Alta (7.8)37%⚠ Explotación activa7 jun 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE…
CVE-2015-4495Alta (8.8)69%⚠ Explotación activa8 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via…
CVE-2013-0422Crítica (9.8)97%⚠ Explotación activa10 ene 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a…
CVE-2010-0840Crítica (9.8)96%⚠ Explotación activa1 abr 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-47337Baja (3.3)0.13%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead…
CVE-2026-47336Baja (3.3)0.13%—28 may 2026
Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in…
CVE-2026-47335Media (5.5)0.13%—28 may 2026
Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic.
CVE-2026-47334Media (5.5)0.10%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in…
CVE-2026-47333Alta (7.8)0.15%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug…
CVE-2026-47332Media (5.5)0.15%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an…
CVE-2026-47331Alta (7.8)0.17%—28 may 2026
Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and,…
CVE-2026-47330Baja (3.3)0.13%—28 may 2026
Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user…
CVE-2026-47329Baja (3.3)0.13%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in…
CVE-2026-47328Media (6.1)0.13%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by…
CVE-2026-47327Baja (3.3)0.13%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel…
CVE-2026-47326Media (5.5)0.13%—28 may 2026
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to…
CVE-2026-31431Alta (7.8)3.4%⚠ Explotación activa22 abr 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…
CVE-2026-3888Alta (7.8)0.18%—17 mar 2026
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This…
CVE-2026-3497Media (6.9)1.3%—12 mar 2026
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project…
CVE-2025-32463Alta (7.8)61%⚠ Explotación activa30 jun 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-5054Media (4.7)0.74%—30 may 2025
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function…
CVE-2023-5616Media (4.9)0.23%—15 abr 2025
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed…
CVE-2022-1804Media (5.5)0.14%—25 mar 2025
accountsservice no longer drops permissions when writting .pam_environment
CVE-2025-26466Media (5.9)40%—28 feb 2025
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key…
CVE-2022-1736Crítica (9.8)0.74%—31 ene 2025
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
CVE-2024-6387Alta (8.1)100%—1 jul 2024
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able…
CVE-2020-27352Alta (8.8)0.26%—21 jun 2024
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these…
CVE-2022-28658Media (5.5)0.20%—4 jun 2024
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
CVE-2022-28657Alta (7.8)0.23%—4 jun 2024
Apport does not disable python crash handler before entering chroot
CVE-2022-28656Media (5.5)0.20%—4 jun 2024
is_closing_session() allows users to consume RAM in the Apport process
CVE-2022-28655Alta (7.1)0.21%—4 jun 2024
is_closing_session() allows users to create arbitrary tcp dbus connections
CVE-2022-28654Media (5.5)0.25%—4 jun 2024
is_closing_session() allows users to fill up apport.log
CVE-2022-28652Media (5.5)0.20%—4 jun 2024
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
CVE-2022-1242Alta (7.8)0.23%—3 jun 2024
Apport can be tricked into connecting to arbitrary sockets as the root user

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System1
  2. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Canonical