Vulnerabilities

Which package version actually fixes it

For twelve pieces of software that run on nearly every Linux server, the advisories that apply to each supported distribution, and the package version that fixes each one. The thing nobody puts in a single place, because each distribution publishes only its own half.

Why this exists

A CVE number is easy to look up and tells you almost nothing useful. What an administrator actually needs is the next step: on the distribution I am running, which package version has the fix, and how do I tell whether I have it. That answer lives in six different advisory trackers using four different version schemes, and it is why a CVE database lookup so often ends in a shrug.

Distributions backport fixes without changing the upstream version, so “OpenSSH 9.6 is old” is not a finding and the package revision after the dash is the part that decides. These pages carry the revision.

Distributions covered

The ones SecAI’s agent supports, each asked separately rather than assumed to match its family.

Ubuntu 22.04 LTSUbuntu 24.04 LTSDebian 12 (bookworm)Debian 13 (trixie)Rocky Linux 9AlmaLinux 9

Software covered

Individual CVEs

Twenty that clear a bar: in CISA’s Known Exploited catalogue, or with a name people actually search for, and affecting a package that runs on real Linux servers. Each says what the bug is, what an attacker gets out of it, and the conditions under which it does not apply to you, because an old package version and a real exposure are different things.

regreSSHionA race condition in sshd, reachable before anyone logs inCVE-2024-6387 · OpenSSHTerrapinAn attacker on the wire can delete the first messages of a sessionCVE-2023-48795 · OpenSSHThe OpenSSH 9.1 double freeIntroduced in one release and fixed in the nextCVE-2023-25136 · OpenSSHThe OpenSSH ProxyCommand injectionA shell metacharacter in a host name, expanded into a commandCVE-2023-51385 · OpenSSHThe xz-utils backdoorA backdoor in the source tarballs, aimed at sshdCVE-2024-3094 · xz-utilsThe mod_rewrite escaping flawA rewrite rule that maps a URL somewhere you did not intendCVE-2024-38475 · Apache HTTP Server · known exploitedHTTP/2 Rapid ResetA protocol flaw that turned into the largest attacks ever recordedCVE-2023-44487 · nginx and Apache · known exploitedLooney TunablesA buffer overflow in the dynamic loader, reachable by any local userCVE-2023-4911 · GNU C Library · known exploitedThe glibc iconv overflowA character-set conversion bug that turned PHP file reads into code executionCVE-2024-2961 · GNU C LibraryThe setuid LD_LIBRARY_PATH flawA search path that should have been ignored, and was notCVE-2025-4802 · GNU C LibraryThe sudo chroot escalationA local root bug in the one program whose job is to hand out root carefullyCVE-2025-32463 · sudo · known exploitedWallEscapeEscape sequences in a broadcast message, painting a fake password promptCVE-2024-28085 · util-linuxThe ncurses terminfo flawA setuid program reading a terminal description the user wroteCVE-2023-29491 · ncursesThe curl SOCKS5 heap overflowAnnounced as the worst curl flaw in years, and narrower than it soundedCVE-2023-38545 · curlThe libcurl ASN.1 time parser readAn out-of-bounds read while parsing a certificate dateCVE-2024-7264 · curlThe libwebp heap overflowOne image library, and an emergency patch across the whole industryCVE-2023-4863 · libwebp · known exploitedThe OpenSSL low-level curve API flawOut-of-bounds memory access, in APIs almost nothing callsCVE-2024-9143 · OpenSSLThe systemd-resolved DNSSEC flawAccepting unsigned records it was configured to rejectCVE-2023-7008 · systemdThe Git link-following flawCloning a repository writes a file where it should notCVE-2025-48384 · Git · known exploitedLeaky VesselsA file descriptor left open, and a container that is no longer containedCVE-2024-21626 · runc

Nothing published before 2023 is here, and that is a correctness rule rather than an editorial one. Debian’s tracker records the version a fix first landed in, which for an older flaw predates every release on this site: a Heartbleed page would print “Debian 12: fixed in 1.0.1g-1”, which is what the advisory says and reads as an upgrade target for a release that shipped patched three major versions later. There is also no per-CVE page for the Linux kernel, where Debian alone carries three thousand advisories and the question “which version fixes it” has a different shape.

What is deliberately not here

  • A page for every CVE. There were 48,185 CVEs published in 2025 alone, six sites already mirror that database, and a page per row would be a worse copy of theirs. Twelve pieces of software and twenty CVEs, written properly, is worth more than twenty thousand generated pages.
  • A count of affected servers. SecAI monitors a small fleet. A percentage drawn from it would be arithmetic on a sample too small to mean anything, and dressing that as a measurement is exactly what these pages exist not to do.
  • Upstream advisory text. Ubuntu’s advisory data is share-alike licensed. Every word of writing here is ours, and the version data is cited as what it is.

Or just find out what you are running

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them. It changes nothing.