Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 20.04 LTS USN-8089-3 ADSys Juju Core LXD Important DoS

ubuntu
Calendar Grey April 7, 2026
Dist Ubuntu Esm H88
Several security issues in ADSys, Juju Core, and LXD for Ubuntu were identified and must be patched immediately to prevent risks.
Several security issues were fixed in ADSys, Juju Core, LXD

Summary

Several security issues were fixed in ADSys, Juju Core, LXD

Software Description:

- adsys: Active Directory Group Policy client

- lxd: Container hypervisor based on LXC

- juju-core: Application orchestration engine

Details:

USN-8089-1 fixed vulnerabilities in Go Networking. This update provides

the corresponding update to code vendored in LXD, ADSys, and Juju Core.

Original advisory details:

Bahruz Jabiyev, Tommaso Innocenti, Anthony Gavazzi, Steven Sprecher, and

Kaan Onarlioglu discovered that servers using Go Networking could hang

during shutdown if preempted by a fatal error. An attacker could possibly

use this to cause a denial of service. This issue only affected Ubuntu

22.04 LTS. (CVE-2022-27664)

Arpad Ryszka and Jakob Ackermann discovered that a maliciously crafted

stream could cause excessive CPU usage in Go Networking's HPACK decoder. An

attacker could possibly use this to cause a denial of service. This issue

only affected Ubuntu 22.04 LTS. (CVE-2022-41723)

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  adsys                           0.9.2~20.04.2ubuntu0.1+esm1
                                  Available with Ubuntu Pro
  adsys-windows                   0.9.2~20.04.2ubuntu0.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  lxd                             3.0.3-0ubuntu1~18.04.2+esm2
                                  Available with Ubuntu Pro
  lxd-client                      3.0.3-0ubuntu1~18.04.2+esm2
                                  Available with Ubuntu Pro
  lxd-tools                       3.0.3-0ubuntu1~18.04.2+esm2
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  golang-github-lxc-lxd-dev       2.0.11-0ubuntu1~16.04.4+esm2
                                  Available with Ubuntu Pro
  juju                            2.3.7-0ubuntu0.16.04.1+esm2
                                  Available with Ubuntu Pro
  juju-2.0                        2.3.7-0ubuntu0.16.04.1+esm2
                                  Available with Ubuntu Pro
  lxc2                            2.0.11-0ubuntu1~16.04.4+esm2
                                  Available with Ubuntu Pro
  lxd                             2.0.11-0ubuntu1~16.04.4+esm2
                                  Available with Ubuntu Pro
  lxd-client                      2.0.11-0ubuntu1~16.04.4+esm2
                                  Available with Ubuntu Pro
  lxd-tools                       2.0.11-0ubuntu1~16.04.4+esm2
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8089-3

https://ubuntu.com/security/notices/USN-8089-2

https://ubuntu.com/security/notices/USN-8089-1

CVE-2021-33194, CVE-2022-27664, CVE-2022-41723, CVE-2023-3978,

CVE-2025-22872, CVE-2025-47911, CVE-2025-58190

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8089-3

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here