LIVE · cybersecurity feed
Live wire
vulnerabilityhigh

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup. The point release covers more than the desktop and server editions. Nine other flavors, including Kubunt

zeroday.news ·

Canonical has released Ubuntu 24.04.5 LTS, an update to its Noble Numbat long-term support distribution, which integrates security updates and stability fixes directly into new installation media. This point release aims to reduce the number of post-installation updates for new deployments.

The 24.04.5 release encompasses not only the standard desktop and server editions but also nine other official flavors, including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio, and Edubuntu. Each of these flavors has its own specific release notes detailing flavor-specific changes alongside the core updates.

Canonical emphasized that the primary focus of this LTS point release is on security corrections and stability improvements, which are critical for a version designed for long-term deployment. Existing users of Ubuntu 22.04 LTS will be offered an automatic upgrade path to 24.04.5 through the Update Manager, which Canonical confirms will remain a free upgrade.

For those planning deployments, it is important to note that the support timelines are tied to the original 24.04 LTS release date, not this point release. Ubuntu Desktop, Ubuntu Server, Ubuntu Cloud, and Ubuntu Core are supported for five years from the initial 24.04 launch. The other flavors receive three years of maintenance. Users requiring support beyond these periods can opt for Expanded Security Maintenance.

Administrators considering whether to perform fresh installations with the 24.04.5 media or allow existing installations to update through their normal cycle should understand that the fixes will reach both paths. The main difference is that new installations using the 24.04.5 media will have these corrections pre-applied, saving a round of downloads immediately after setup.

The release notes for Ubuntu 24.04.5 do not explicitly list specific CVEs or bug IDs. Administrators needing to verify particular patches for compliance purposes are directed to consult the linked release notes for more detailed information.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice