Ubuntu Support Template
Ubuntu version 26.04
Desktop Environment GNOME
Problem Description:
I have a subscription to Ubuntu Pro on my Ubuntu 26.04 desktop. A ‘pro status’ enquiry shows ‘esm-apps’, ‘esm-infra’ and ‘livepatch’ all enabled. I have also run a software update. When I run a ‘pro cves’ scan several things puzzle me. First, 11 vulnerabilities show up marked as critical and 6 of these occur in 12 different packages.
For example:
linux-headers-7.0.0-27-generic critical - CVE-2026-31608
linux-headers-7.0.0-27-generic critical - CVE-2026-43501
linux-headers-7.0.0-27-generic critical - CVE-2026-45988
linux-headers-7.0.0-27-generic critical - CVE-2026-46043
linux-headers-7.0.0-27-generic critical - CVE-2026-46135
linux-headers-7.0.0-27-generic critical - CVE-2026-52955
linux-headers-7.0.0-27-generic critical - CVE-2026-52989
linux-headers-7.0.0-27-generic critical - CVE-2026-52993
linux-headers-7.0.0-27-generic critical - CVE-2026-53002
linux-headers-7.0.0-27-generic critical - CVE-2026-53215
linux-headers-7.0.0-27-generic critical - CVE-2026-53260
When I run ‘pro fix CVE-2026-XXXXX’ on each vulnerability I get a result saying all except for the last 2 of them are fixed (or at least that’s how I interpret the message).
For example:
CVE-2026-31608: Linux kernel vulnerabilities
- https://ubuntu.com/security/CVE-2026-31608
1 affected source package is installed: linux
(1/1) linux:
A fix is available in Ubuntu standard updates.
The update is already installed.
✔ CVE-2026-31608 is resolved.
The message for the remaining 2 vulnerabilities (CVE-2026-53215 and -53260) says an update is coming tomorrow.
After a reboot the pro cves scan results are exactly the same.
Another thing, why is there no information under the ‘Origin’ column? Does my machine have a CVE problem or not?
Cheers,
Malcolm