Known vulnerabilities in linux-fips (Ubuntu package) - page 43
Vendor:
Canonical Ltd.
Software:
linux-fips (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:linux-fips_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
1273
Public exploits:
7
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.15.0.1110.109
5.15.0.190.111
5.15.0-190.200+fips1
5.15.0-1110.116
4.4.0.1127.129
4.4.0-1127.134
6.8.0-136.136.2~22.04.1
6.8.0-136.136.2
6.8.0-136.136+fips2
6.8.0-1058.61
4.4.0.1125.127
4.4.0-1125.132
6.8.0-116.116+fips1
5.15.0.1105.95
5.15.0.176.102
5.15.0-176.186+fips1
5.15.0-1105.114+fips1
4.4.0.1123.124
4.4.0-1123.130
5.4.0.1159.101
5.4.0.1130.127
5.4.0-1159.168+fips1
5.4.0-1130.140
4.4.0.1122.123
4.4.0-1122.129
5.15.0.171.98
5.15.0-171.181+fips1
6.8.0-1048.51+fips1
6.8.0-101.101+fips1
4.4.0.1121.122
4.4.0-1121.128
4.4.0.1120.121
4.4.0-1120.127
4.4.0.1119.120
4.4.0-1119.126
5.4.0.1154.96
5.4.0.1125.122
5.4.0-1154.163+fips1
5.4.0-1125.135
4.4.0.1117.118
4.4.0-1117.124
4.4.0.1116.117
4.4.0-1116.123
4.4.0.1115.116
4.4.0-1115.122
4.15.0.1136.133
4.15.0-1136.147
4.4.0.1114.115
4.4.0-1114.121
4.4.0.1113.114
4.4.0-1113.120
Vulnerabilities (1273)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124511 - Use After Free CVE-2026-23340 |
CWE-416 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB20260325120 SB20260513116 SB2026051411 and 32 more |
||
| #VU124510 - Missing release of memory after effective lifetime CVE-2026-23339 |
CWE-401 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB20260325119 SB20260513116 SB2026051411 and 28 more |
||
| #VU124505 - Resource exhaustion CVE-2026-23347 |
CWE-400 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB20260325110 SB20260513116 SB20260721108 and 13 more |
||
| #VU124501 - Integer overflow CVE-2026-23343 |
CWE-190 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB20260325104 SB2026041129 SB2026041130 and 19 more |
||
| #VU124495 - Type conversion CVE-2026-23352 |
CWE-704 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032598 SB2026040337 SB20260513116 and 29 more |
||
| #VU124490 - Improper Resource Shutdown or Release CVE-2026-23360 |
CWE-404 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032593 SB20260513116 SB20260522107 and 13 more |
||
| #VU124489 - Out-of-bounds write CVE-2026-23359 |
CWE-787 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032592 SB20260513116 SB2026051411 and 27 more |
||
| #VU124486 - On-Chip Debug and Test Interface With Improper Access Control CVE-2026-23357 |
CWE-1191 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032589 SB20260513116 SB2026051411 and 28 more |
||
| #VU124485 - Unchecked Return Value to NULL Pointer Dereference CVE-2026-23356 |
CWE-690 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032588 SB20260513116 SB2026051411 and 26 more |
||
| #VU124481 - Uncontrolled Recursion CVE-2026-23365 |
CWE-674 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032583 SB2026041129 SB2026041130 and 31 more |
||
| #VU124479 - Observable discrepancy CVE-2026-23364 |
CWE-203 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032582 SB2026041132 SB20260513116 and 15 more |
||
| #VU124477 - Out-of-bounds write CVE-2026-23363 |
CWE-787 | Medium | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032581 SB20260513116 SB2026060229 and 15 more |
||
| #VU124476 - Memory corruption CVE-2026-23362 |
CWE-119 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032580 SB2026041129 SB2026041130 and 32 more |
||
| #VU124474 - Improper Synchronization CVE-2026-23361 |
CWE-662 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032579 SB2026042426 SB20260430100 and 16 more |
||
| #VU124471 - Use After Free CVE-2026-23372 |
CWE-416 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032577 SB20260513116 SB2026051411 and 28 more |
||
| #VU124468 - Exposure of Private Information ('Privacy Violation') CVE-2026-23370 |
CWE-359 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032575 SB20260513116 SB2026051411 and 28 more |
||
| #VU124467 - NULL Pointer Dereference CVE-2026-23369 |
CWE-476 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032574 SB20260513116 SB20260721108 and 13 more |
||
| #VU124466 - Incorrect Register Defaults or Module Parameters CVE-2026-23368 |
CWE-1221 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032573 SB2026041129 SB2026041130 and 31 more |
||
| #VU124465 - Use of Uninitialized Variable CVE-2026-23367 |
CWE-457 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032572 SB20260513116 SB2026051411 and 28 more |
||
| #VU124459 - Improper Synchronization CVE-2026-23374 |
CWE-662 | Low | 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61 | 25.03.2026 |
SB2026032566 SB20260513116 SB20260522107 and 17 more |
Showing elements 841 - 860 out of 1273