Linuxsecurity Ubuntu 22.04 LTS OpenSBI Denial of Service Vulnerability Disclosed
Article Content
Browse articles
- •OpenSBI vulnerability allows denial of service on Ubuntu 22.04 LTS.
- •Affected systems must update to OpenSBI version 1.3-1ubuntu0.22.04.3.
- •No active exploitation has been reported as of now.
A vulnerability in OpenSBI was discovered that allows an attacker to cause a denial of service by sending specially crafted input. This flaw affects Ubuntu 22.04 LTS systems running OpenSBI versions prior to 1.3-1ubuntu0.22.04.3. The issue arises from improper validation of the counter index mask in SBI PMU extension requests. Users are advised to update their systems to mitigate this risk. A standard system update will apply the necessary changes. No has been reported at this time. The vulnerability has been assigned the identifier USN-8853-1.
Ask AI about this cluster
Answers cite the sources they use
Updated just now How this analysis works
Timeline
2026-09-30
Vulnerability disclosed
OpenSBI vulnerability affecting Ubuntu 22.04 LTS was disclosed, allowing denial of service through crafted input.
Linuxsecurity2026-09-30
Patch released
Ubuntu released a patch for OpenSBI, updating it to version 1.3-1ubuntu0.22.04.3 to address the vulnerability.
UbuntuMore articles in this cluster (2)
Following this threat?
Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of OpenSBI are affected?
OpenSBI versions prior to 1.3-1ubuntu0.22.04.3 on Ubuntu 22.04 LTS are affected.
Is there a patch available?
Yes, users should update to OpenSBI version 1.3-1ubuntu0.22.04.3 to mitigate the vulnerability.
Has this vulnerability been exploited in the wild?
No active exploitation has been reported at this time.
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…