---
title: Blog posts tagged "CVE"
description: Canonical makes open source secure, reliable and easy to use, providing
  support for Ubuntu and a portfolio of enterprise-grade technologies. Founded in
  2004, Canonical operates globally with team members in over 80 countries.
url: https://canonical.com/blog/tag/cve?format=md
---

# Blog posts tagged "CVE"

#### [Zenbleed vulnerability fix for Ubuntu](https://canonical.com/blog/ubuntu-zenbleed-security-fix)

On 24 July 2023, security researchers from Google’s Information Security Engineering team disclosed a hardware vulnerability affecting AMD’s Zen 2 family of microprocessors. They dubbed this vulnerability “Zenbleed” (CVE-2023-20593), evoking memories of previous vulnerabilities like HeartBleed and hinting at its possible impact. In respon

---

Cloud and server

#### [Canonical joins the Eclipse Foundation’s Software Defined Vehicle working group](https://canonical.com/blog/canonical-joins-the-eclipse-foundations-software-defined-vehicle-working-group)

Canonical is excited to announce it is now an official member of the Eclipse Software Defined Vehicle Working Group (SDV WG). Eclipse SDV focuses on software-defined vehicles (SDVs) and pushes innovations in automotive-grade solutions using open-source software. By offering an open technology platform, automotive companies can use and int

---

Company

#### [Security vulnerabilities on the Data Distribution Service (DDS)](https://canonical.com/blog/security-vulnerabilities-on-the-data-distribution-service-dds)

Learn more about DDS, and how to stay protected while using it If you are currently running the Robot Operating System 2 (ROS 2), this piece is especially relevant to the security of your robots. A few weeks ago, a group of security researchers reported 13 security vulnerabilities affecting some of the most used implementations

---

Robotics

#### [Enhance the security of your open-source applications and share feedback](https://canonical.com/blog/enhance-security-of-open-source-applications)

Are you spending time on high-impact, high-value activities, or are you constantly derailed by maintenance, support, and deployment challenges? Does your organisation consume open-source software that needs security patching? Where do you get the security updates from, and how do you track what’s available? Are you responsible for vulnera

---

Company

#### [ROS CVE alert; ensuring security for robotics](https://canonical.com/blog/ros-cve-alert-ensuring-security-for-robotics)

Security for robotics is a priority for ROS developers and crucial for the success of robotics. Open Robotics has registered a CVE that affects ROS Kinetic, Melodic and Noetic. CVE stands for Common Vulnerabilities and Exposures, and it’s an international system that provides a method for publicly sharing information on cybersecurity vuln

---

Robotics

#### [What lies on the second phase of Ubuntu LTS? Two years of Ubuntu 14.04 in ESM](https://canonical.com/blog/what-lies-after-lts-two-years-of-ubuntu-14-04-in-esm)

Two years ago, we launched the Extended Security Maintenance (ESM) phase of Ubuntu 14.04, providing access to CVE patches through an Ubuntu Advantage for Infrastructure free or paid subscription. This phase extended the lifecycle of Ubuntu 14.04 LTS, released in April 2014, to a total of ten years, ending in April 2024. During the ESM

---

Security

#### [Mitigating BootHole – ‘There’s a hole in the boot’ – CVE-2020-10713 and related vulnerabilities](https://canonical.com/blog/mitigating-boothole-theres-a-hole-in-the-boot-cve-2020-10713-and-related-vulnerabilities)

Responsible disclosure and coordinated response as a benefit to all Today we released USN-4432-1 announcing updates for a series of vulnerabilities termed BootHole / ‘There’s a hole in the boot’ in GRUB2 (GRand Unified Bootloader version 2) that could allow an attacker to subvert UEFI Secure Boot. The original vulnerability, CVE-2020-1071

---

Cloud and server

#### [FIPS 140-2: Stay compliant and secure with Canonical](https://canonical.com/blog/fips-140-2-stay-compliant-and-secure-with-canonical)

FIPS 140-2 is a set of publicly announced cryptographic standards developed by the National Institute of Standards and Technology. It is an essential part of FEDRamp requirements for many governmental agencies in the US and Canada, as well as their business partners from all around the world. Furthermore, as a well established and verifie

---

Cloud and server

#### [Charmed Kubernetes update for upstream API server vulnerability](https://canonical.com/blog/charmed-kubernetes-update-for-upstream-api-server-vulnerability)

An upstream Kubernetes vulnerability (CVE-2019-11247) has been identified where the API server mistakenly allows access to a cluster-scoped custom resource, if the request is made as if the resource were namespaced. Authorisations for the resource accessed in this manner are enforced using roles and role bindings within the namespace. Thi

---

Cloud and server

#### [Ubuntu 14.04 LTS has transitioned to ESM support](https://canonical.com/blog/ubuntu-14-04-esm-support)

Extended Security Maintenance (ESM) is now available for Ubuntu 14.04 LTS to provide ongoing security patches for high and critical CVEs for UA Infrastructure customers.

---

Cloud and server

#### [Security Team Weekly Summary: November 9, 2017](https://canonical.com/blog/security-team-weekly-summary-november-9-2017)

The Security Team weekly reports are intended to be very short summaries of the Security Team’s weekly activities. If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively, you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com During the last week

---

Cloud and server

#### [Security Team Weekly Summary: November 2, 2017](https://canonical.com/blog/security-team-weekly-summary-november-2-2017)

The Security Team weekly reports are intended to be very short summaries of the Security Team’s weekly activities. If you would like to reach the Security Team, you can find us at the #ubuntu-hardened channel on FreeNode. Alternatively, you can mail the Ubuntu Hardened mailing list at: ubuntu-hardened@lists.ubuntu.com During the last week

---

Cloud and server

#### [Kernel Team Summary: June 22, 2017](https://canonical.com/blog/kernel-team-summary-june-22-2017)

This newsletter is to provide a status update from the Ubuntu Kernel Team. There will also be highlights provided for any interesting subjects the team may be working on. If you would like to reach the kernel team, you can find us at the #ubuntu-kernel channel on FreeNode. Alternatively, you can mail the Ubuntu Kernel

---

Cloud and server

#### [Kernel Team Summary- June 8, 2017](https://canonical.com/blog/kernel-team-summary-june-8-2017)

Introduction This newsletter is to provide a status update from the Ubuntu Kernel Team. There will also be highlights provided for any interesting subjects the team may be working on. If you would like to reach the kernel team, you can find us at the #ubuntu-kernel channel on FreeNode. Alternatively, you can mail the Ubuntu

---

Cloud and server
