---
title: Blog posts tagged "Vulnerabilities"
description: Canonical makes open source secure, reliable and easy to use, providing
  support for Ubuntu and a portfolio of enterprise-grade technologies. Founded in
  2004, Canonical operates globally with team members in over 80 countries.
url: https://canonical.com/blog/tag/vulnerabilities?format=md
---

# Blog posts tagged "Vulnerabilities"

#### [Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID CVE-2026-53359 and is referred to as Januscape. This vulnerability affects all Ubuntu releases. Neither NVD nor Kernel.org have published their own CVSS scores for this issu

---

Security and Compliance

#### [DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed to the Linux kernel maintainers and the CVE record published on May 23, 2026. The vulnerability affects multiple Linux distributions, including all Ubuntu releases.

---

Security and Compliance

#### [pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE) vulnerability on June 26, 2026. Known as “pedit COW”, this vulnerability affects multiple Linux distributions, including all Ubuntu releases starting with Bionic Be

---

Security and Compliance

#### [PinTheft Linux kernel vulnerability mitigation](https://canonical.com/blog/pintheft-linux-kernel-vulnerability-mitigation)

A local privilege escalation (LPE) security vulnerability in the Linux kernel, codename “PinTheft,” was publicly disclosed on May 19, 2026. The vulnerability was fixed in the mainline Linux kernel tree. A proof-of-concept exploit was published along with public disclosure. This has been assigned the CVE ID CVE-2026-43494; other discoverin

---

Company

#### [CVE-2026-46333 (ssh-keysign-pwn) Linux kernel vulnerability mitigations](https://canonical.com/blog/ssh-keysign-pwn-linux-vulnerability-fixes-available)

An information disclosure security vulnerability in the Linux kernel was publicly disclosed on May 15th, 2026. The vulnerability was reported by Qualys and fixed in the mainline Linux kernel tree. A proof-of-concept exploit was published soon after public disclosure. The ID CVE-2026-46333 was assigned, but the vulnerability is also referr

---

Company

#### [Finding the blind spot: How Canonical hunts logic flaws with AI](https://canonical.com/blog/finding-the-blind-spot-how-canonical-hunts-logic-flaws-with-ai)

AI is accelerating and improving how security engineers find and fix vulnerabilities. A new tool developed and used at Canonical, called Redhound, has already uncovered three critical logic vunerabilites, paving the way for a more secure software landscape.

---

AI

#### [Fragnesia Linux kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/fragnesia-linux-vulnerability-fixes-available)

A local privilege escalation (LPE) vulnerability affecting the Linux kernel has been publicly disclosed on May 13, 2026. The vulnerability has been assigned the CVE ID CVE-2026-46300 and is referred to as “Fragnesia.”  The vulnerability affects multiple Linux distributions, including all Ubuntu releases. The affected components are the Li

---

Company

#### [Dirty Frag Linux kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/dirty-frag-linux-vulnerability-fixes-available)

Two local privilege escalation (LPE) vulnerabilities affecting the Linux kernel have been publicly disclosed on May 7, 2026. The vulnerabilities have been assigned the IDs CVE-2026-43284 and CVE-2026-43500 and are referred to as “Dirty Frag.” The affected components are Linux kernel modules. The first vulnerability impacts the modules tha

---

Company

#### [Fixes available for CVE-2026-31431 (Copy Fail) Linux Kernel Local Privilege Escalation Vulnerability](https://canonical.com/blog/copy-fail-vulnerability-fixes-available)

A local privilege escalation (LPE) vulnerability affecting the Linux kernel has been publicly disclosed on April 29, 2026. The vulnerability has been assigned CVE ID CVE-2026-31431 and is referred to as Copy Fail. The affected component is a kernel module that provides hardware-accelerated cryptographic functions: algif\_aead. The vulnerab

---

Company

#### [AppArmor vulnerability fixes available](https://canonical.com/blog/apparmor-vulnerability-fixes-available)

Qualys discovered several vulnerabilities in the AppArmor code of the Linux kernel. These are being referred to as CrackArmor, while CVE IDs are in the process of being assigned by the Linux Kernel CVE Numbering Authority. There are eleven patches for the nine vulnerabilities and each patch is assigned a CVE IDs: CVE-2026-23268, CVE-2026-

---

Company

#### [What are dependencies, and how do you secure them?](https://canonical.com/blog/what-are-dependencies)

There are thousands of free-to-use, ready-built programs and code repositories that solve  problems you’d otherwise need to spend weeks building the solutions for from scratch. However, like with all software, you still need to ensure that your software supply chain is secure and safe to consume.

---

Security

#### [Fixes available for local privilege escalation vulnerability in libblockdev using udisks](https://canonical.com/blog/udisks-libblockdev-lpe-vulnerability-fixes-available)

Qualys discovered two vulnerabilities in various Linux distributions which allow local attackers to escalate privileges. The first vulnerability (CVE-2025-6018) was found in the PAM configuration. This CVE does not impact default Ubuntu installations because of how the pam\_systemd.so and pam\_env.so modules are invoked. The second vulnerab

---

Company

#### [Apport local information disclosure vulnerability fixes available](https://canonical.com/blog/apport-local-information-disclosure-vulnerability-fixes-available)

Qualys discovered two vulnerabilities in various Linux distributions which allow a local attacker with permission to create user namespaces to leak core dumps for processes of suid executables. These affect both apport, the Ubuntu default core dump handler (CVE-2025-5054), and systemd-coredump, the default core dump handler in Red Hat Ent

---

Company

#### [Rsync remote code execution and related vulnerability fixes available](https://canonical.com/blog/rsync-remote-code-execution)

Canonical’s security team has released updates of the rsync packages for all supported Ubuntu releases. The updates remediate CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, and CVE-2024-12747.

---

Hardening

#### [What is vulnerability management?](https://canonical.com/blog/what-is-vulnerability-management)

Vulnerability management is the holistic process of identifying and handling security risks in an organization’s networks, systems and devices. Vulnerability management serves an overarching strategy that describes and outlines the many individual efforts and steps taken to reduce cyber incident risk to acceptable levels and improve overa

---

Security

#### [Needrestart local privilege escalation vulnerability fixes available](https://canonical.com/blog/needrestart-local-privilege-escalation)

Qualys discovered vulnerabilities which allow a local attacker to gain root privileges in the needrestart package (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, and CVE-2024-11003) and a related issue in libmodule-scandeps-perl (CVE-2024-10224). The vulnerabilities affect Debian, Ubuntu and other Linux distributions. Canonical’s securit

---

Company

1. *Previous page*
2. [1](https://canonical.com/blog/tag/vulnerabilities?format=md&page=1)
3. [2](https://canonical.com/blog/tag/vulnerabilities?format=md&page=2)
4. [*Next page*](https://canonical.com/blog/tag/vulnerabilities?format=md&page=2)
