Ubuntu OVAL Security Dashboard
Canonical USN advisories across every current Ubuntu LTS release — explore risk, support lifecycle / expirations and affected dependencies. All processing is local.
Search
Coverage
Release
Severity
Attack vector
OVAL coverage — every file & scope
All published Canonical OVAL documents in this directory, across three scopes — USN advisories, CVE per-CVE assessments and PKG per-package exposure — for every release and product line (Archive, OCI images, FIPS, Realtime, Bluefield).
Coverage matrix
Product line × release — which scopes are published, and CVE volume (cell tint).
What's inside
OVAL definitions by scope and by product line.
All OVAL files
Filter by scope, product base and variant; sort any column.
VEX — exploitability status (OpenVEX)
Canonical also publishes its security data in the OpenVEX format (one JSON document per USN and per CVE). VEX complements OVAL: it asserts each package's status — fixed, affected, not affected, under investigation — but carries no severity or CVSS; risk scoring stays with the OVAL feed.
CVE statement status
All statements across the per-CVE VEX corpus.
Release × channel coverage
USN VEX product references by release and update channel — VEX names ESM, FIPS and realtime channels explicitly in each package URL.
“Not affected” — why
Machine-readable OpenVEX justifications.
OVAL ↔ VEX agreement
The two feeds describe the same advisories — same USN ids, CVEs and packages — in different shapes: OVAL adds severity/CVSS and machine-checkable tests; VEX adds per-status assertions with justifications and finer channel detail.
Release lifecycle & support expirations
Standard LTS support → Expanded Security Maintenance (ESM, via Ubuntu Pro). Bar accent width below each row = advisory volume. The dashed line marks today.
Advisories over time
USNs by month, stacked by severity. Toggle severities in the legend.
Severity by release
Share of advisories at each severity.
Risk profile (CVSS)
Worst CVSS score per advisory.
Attack vector
How the worst CVE is reached.
Coverage: LTS vs ESM
Free fixes vs. Ubuntu Pro.
Most-patched components
Top dependencies by advisory count in the current selection.
Shared CVE exposure
How many LTS releases each fixed CVE spans — wider = broader fleet risk.
Advisories
Sortable. Select a USN to open the notice on ubuntu.com.
Built from Canonical's published USN OVAL data (MITRE OVAL 5.11.1). Severity is Canonical's advisory rating; CVSS is the v3 base score of the most severe CVE per advisory. “ESM” fixes are delivered through Ubuntu Pro. Lifecycle dates follow Canonical's LTS / ESM schedule; 26.04 dates are projected. Interface built with the Vanilla framework.