Canonical
Canonical Ubuntu Linux: vulnerabilidades y CVE
Canonical Ubuntu Linux tiene 4120 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 345 son críticas y 46 figuran en el catálogo de explotación activa de CISA.
CVE4120
Últimos 12 meses15
Críticas345
Explotadas activamente46
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0492 | Alta (7.8) | 5.5% | ⚠ Explotación activa | 3 mar 2022 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to… |
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2018-14634 | Alta (7.8) | 15% | ⚠ Explotación activa | 25 sept 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on… |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2023-0386 | Alta (7.8) | 7.9% | ⚠ Explotación activa | 22 mar 2023 | A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid… |
| CVE-2016-3714 | Alta (8.4) | 97% | ⚠ Explotación activa | 5 may 2016 | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell… |
| CVE-2022-2586 | Alta (7.8) | 10% | ⚠ Explotación activa | 8 ene 2024 | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. |
| CVE-2023-4911 | Alta (7.8) | 81% | ⚠ Explotación activa | 3 oct 2023 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES… |
| CVE-2014-0196 | Media (5.5) | 22% | ⚠ Explotación activa | 7 may 2014 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory… |
| CVE-2021-3560 | Alta (7.8) | 24% | ⚠ Explotación activa | 16 feb 2022 | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker… |
| CVE-2016-8735 | Crítica (9.8) | 90% | ⚠ Explotación activa | 6 abr 2017 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX… |
| CVE-2016-3427 | Crítica (9.8) | 92% | ⚠ Explotación activa | 21 abr 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2010-3904 | Alta (7.8) | 14% | ⚠ Explotación activa | 6 dic 2010 | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which… |
| CVE-2021-3493 | Alta (7.8) | 49% | ⚠ Explotación activa | 17 abr 2021 | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged… |
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2016-1646 | Alta (8.8) | 48% | ⚠ Explotación activa | 29 mar 2016 | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of… |
| CVE-2014-3153 | Alta (7.8) | 37% | ⚠ Explotación activa | 7 jun 2014 | The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE… |
| CVE-2015-4495 | Alta (8.8) | 69% | ⚠ Explotación activa | 8 ago 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via… |
| CVE-2013-0422 | Crítica (9.8) | 97% | ⚠ Explotación activa | 10 ene 2013 | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a… |
| CVE-2010-0840 | Crítica (9.8) | 96% | ⚠ Explotación activa | 1 abr 2010 | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-47337 | Baja (3.3) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead… |
| CVE-2026-47336 | Baja (3.3) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in… |
| CVE-2026-47335 | Media (5.5) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic. |
| CVE-2026-47334 | Media (5.5) | 0.10% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in… |
| CVE-2026-47333 | Alta (7.8) | 0.15% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug… |
| CVE-2026-47332 | Media (5.5) | 0.15% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an… |
| CVE-2026-47331 | Alta (7.8) | 0.17% | — | 28 may 2026 | Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and,… |
| CVE-2026-47330 | Baja (3.3) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user… |
| CVE-2026-47329 | Baja (3.3) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in… |
| CVE-2026-47328 | Media (6.1) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by… |
| CVE-2026-47327 | Baja (3.3) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel… |
| CVE-2026-47326 | Media (5.5) | 0.13% | — | 28 may 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to… |
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2026-3888 | Alta (7.8) | 0.18% | — | 17 mar 2026 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This… |
| CVE-2026-3497 | Media (6.9) | 1.3% | — | 12 mar 2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project… |
| CVE-2025-32463 | Alta (7.8) | 61% | ⚠ Explotación activa | 30 jun 2025 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
| CVE-2025-5054 | Media (4.7) | 0.74% | — | 30 may 2025 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function… |
| CVE-2023-5616 | Media (4.9) | 0.23% | — | 15 abr 2025 | In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed… |
| CVE-2022-1804 | Media (5.5) | 0.14% | — | 25 mar 2025 | accountsservice no longer drops permissions when writting .pam_environment |
| CVE-2025-26466 | Media (5.9) | 40% | — | 28 feb 2025 | A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key… |
| CVE-2022-1736 | Crítica (9.8) | 0.74% | — | 31 ene 2025 | Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. |
| CVE-2024-6387 | Alta (8.1) | 100% | — | 1 jul 2024 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able… |
| CVE-2020-27352 | Alta (8.8) | 0.26% | — | 21 jun 2024 | When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these… |
| CVE-2022-28658 | Media (5.5) | 0.20% | — | 4 jun 2024 | Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing |
| CVE-2022-28657 | Alta (7.8) | 0.23% | — | 4 jun 2024 | Apport does not disable python crash handler before entering chroot |
| CVE-2022-28656 | Media (5.5) | 0.20% | — | 4 jun 2024 | is_closing_session() allows users to consume RAM in the Apport process |
| CVE-2022-28655 | Alta (7.1) | 0.21% | — | 4 jun 2024 | is_closing_session() allows users to create arbitrary tcp dbus connections |
| CVE-2022-28654 | Media (5.5) | 0.25% | — | 4 jun 2024 | is_closing_session() allows users to fill up apport.log |
| CVE-2022-28652 | Media (5.5) | 0.20% | — | 4 jun 2024 | ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack |
| CVE-2022-1242 | Alta (7.8) | 0.23% | — | 3 jun 2024 | Apport can be tricked into connecting to arbitrary sockets as the root user |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.