Known vulnerabilities in linux-fips (Ubuntu package)
Vendor:
Canonical Ltd.
Software:
linux-fips (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:linux-fips_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
1273
Public exploits:
7
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.15.0.1110.109
5.15.0.190.111
5.15.0-190.200+fips1
5.15.0-1110.116
4.4.0.1127.129
4.4.0-1127.134
6.8.0-136.136.2~22.04.1
6.8.0-136.136.2
6.8.0-136.136+fips2
6.8.0-1058.61
4.4.0.1125.127
4.4.0-1125.132
6.8.0-116.116+fips1
5.15.0.1105.95
5.15.0.176.102
5.15.0-176.186+fips1
5.15.0-1105.114+fips1
4.4.0.1123.124
4.4.0-1123.130
5.4.0.1159.101
5.4.0.1130.127
5.4.0-1159.168+fips1
5.4.0-1130.140
4.4.0.1122.123
4.4.0-1122.129
5.15.0.171.98
5.15.0-171.181+fips1
6.8.0-1048.51+fips1
6.8.0-101.101+fips1
4.4.0.1121.122
4.4.0-1121.128
4.4.0.1120.121
4.4.0-1120.127
4.4.0.1119.120
4.4.0-1119.126
5.4.0.1154.96
5.4.0.1125.122
5.4.0-1154.163+fips1
5.4.0-1125.135
4.4.0.1117.118
4.4.0-1117.124
4.4.0.1116.117
4.4.0-1116.123
4.4.0.1115.116
4.4.0-1115.122
4.15.0.1136.133
4.15.0-1136.147
4.4.0.1114.115
4.4.0-1114.121
4.4.0.1113.114
4.4.0-1113.120
Vulnerabilities (1273)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139868 - Improper input validation CVE-2026-64531 |
CWE-20 | Low | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 28.07.2026 |
SB2026072861 SB2026080379 SB2026080772 and 29 more |
||
| #VU136962 - Use After Free CVE-2026-53359 |
CWE-416 | Low | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 07.07.2026 |
SB2026070736 SB2026070739 SB2026070740 and 97 more |
||
| #VU135620 - Out-of-bounds write CVE-2026-53176 |
CWE-787 | Medium | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB20260626180 SB2026070969 SB20260721153 and 39 more |
||
| #VU135580 - Use After Free CVE-2026-53212 |
CWE-416 | Low | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB20260626131 SB2026081482 SB2026081486 and 27 more |
||
| #VU135561 - Use After Free CVE-2026-53215 |
CWE-416 | Low | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB20260626112 SB20260721153 SB2026072258 and 21 more |
||
| #VU135550 - Use After Free CVE-2026-53228 |
CWE-416 | Low | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB20260626107 SB2026080363 SB2026081482 and 35 more |
||
| #VU135540 - Out-of-bounds read CVE-2026-53225 |
CWE-125 | Medium | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB20260626103 SB20260721153 SB2026072258 and 35 more |
||
| #VU135535 - Out-of-bounds read CVE-2026-53224 |
CWE-125 | Medium | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB2026062699 SB20260721153 SB2026072258 and 95 more |
||
| #VU135508 - Out-of-bounds read CVE-2026-53246 |
CWE-125 | Medium | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 26.06.2026 |
SB2026062679 SB20260721153 SB2026072258 and 98 more |
||
| #VU135452 - Use After Free CVE-2026-52924 |
CWE-416 | Medium | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 25.06.2026 |
SB20260625264 SB2026071053 SB2026071101 and 41 more |
||
| #VU134602 - Out-of-bounds write CVE-2026-46331 |
CWE-787 | Low | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 16.06.2026 |
SB2026061647 SB20260619116 SB20260619130 and 103 more |
||
| #VU133323 - Improper input validation CVE-2026-46266 |
CWE-20 | Medium | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 04.06.2026 |
SB2026060414 SB2026070282 SB2026070283 and 51 more |
||
| #VU131905 - Improper Check or Handling of Exceptional Conditions CVE-2026-43493 |
CWE-703 | Low | 4.4.0.1127.129, 4.4.0-1127.134 | 20.05.2026 |
SB2026052001 SB20260529221 SB20260529225 and 44 more |
||
| #VU130813 - Use After Free CVE-2026-43378 |
CWE-416 | Low | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 09.05.2026 |
SB2026050921 SB2026070282 SB2026070283 and 24 more |
||
| #VU130542 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-43198 |
CWE-362 | Medium | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 07.05.2026 |
SB20260507153 SB2026061290 SB2026061291 and 54 more |
||
| #VU127744 - Integer underflow CVE-2026-31649 |
CWE-191 | Low | 4.4.0.1127.129, 4.4.0-1127.134 | 25.04.2026 |
SB2026042562 SB20260513116 SB2026051411 and 42 more |
||
| #VU127703 - Improper control of a resource through its lifetime CVE-2026-31448 |
CWE-664 | Low | 4.4.0.1127.129, 4.4.0-1127.134, 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 24.04.2026 |
SB20260424283 SB20260513116 SB2026051411 and 39 more |
||
| #VU126567 - Observable discrepancy CVE-2025-54505 |
CWE-203 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 20.04.2026 |
SB2026042081 SB20260428235 SB2026042901 and 39 more |
||
| #VU114098 - Insufficient Verification of Data Authenticity CVE-2025-27558 |
CWE-345 | Medium | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 15.08.2025 |
SB2025081505 SB2025081507 SB2025081508 and 22 more |
||
| #VU53098 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2020-24588 |
CWE-451 | Low | 5.15.0.190.111, 5.15.0-190.200+fips1, 5.15.0.1110.109, 5.15.0-1110.116 | 11.05.2021 |
SB2021051118 SB2021051227 SB2021051708 and 59 more |
Showing elements 1 - 20 out of 1273