Ubuntu 16.04 'Xenial Xerus' (LTS)
Ubuntu 16.04 'Xenial Xerus' (LTS)
The Ubuntu 16.04 'Xenial Xerus' (LTS) reached end of service life on Apr 2, 2026 — Ubuntu no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Ubuntu 16.04 'Xenial Xerus' (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- ubuntu
- release
- 16.04
- product Label
- Ubuntu
- release Label
- 16.04 'Xenial Xerus' (LTS)
- codename
- Xenial Xerus
- lts
- true
- latest Version
- 16.04.7
- release Date
- 2016-04-21
- maintained
- source Url
- https://endoflife.date/ubuntu
Lifecycle Dates
- End of Service Life
- Apr 2, 2026
- Last OEM Support
- Apr 2, 2021
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Ubuntu 16.04 'Xenial Xerus' (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Ubuntu 16.04 'Xenial Xerus' (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Ubuntu 16.04 'Xenial Xerus' (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Ubuntu 16.04 'Xenial Xerus' (LTS) Support: Frequently Asked Questions
Is the Ubuntu 16.04 'Xenial Xerus' (LTS) still supported?
Ubuntu ended support for the Ubuntu 16.04 'Xenial Xerus' (LTS) on Apr 2, 2026 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Ubuntu 16.04 'Xenial Xerus' (LTS) end of service life (EOSL) date?
Ubuntu lists the end of service life for the Ubuntu 16.04 'Xenial Xerus' (LTS) as Apr 2, 2026.
Can I keep using the Ubuntu 16.04 'Xenial Xerus' (LTS) after its EOSL date?
Yes. EOSL means Ubuntu stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Ubuntu 16.04 'Xenial Xerus' (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Ubuntu 16.04 'Xenial Xerus' (LTS)
2239 published CVEs affect the Ubuntu 16.04 'Xenial Xerus' (LTS), including 1077 rated critical or high severity. Ubuntu no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2023-1523 | CRITICAL | 10.0 | Sep 1, 2023 | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console. |
| CVE-2018-18505 | CRITICAL | 10.0 | Feb 5, 2019 | An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability a |
| CVE-2017-16845 | CRITICAL | 10.0 | Nov 17, 2017 | hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. |
| CVE-2020-11984 | CRITICAL | 9.8 | Aug 7, 2020 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
| CVE-2017-18922 | CRITICAL | 9.8 | Jun 30, 2020 | It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow. |
| CVE-2020-6831 | CRITICAL | 9.8 | May 26, 2020 | A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. |
| CVE-2020-12395 | CRITICAL | 9.8 | May 26, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. |
| CVE-2020-10683 | CRITICAL | 9.8 | May 1, 2020 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. |
| CVE-2020-11651 | CRITICAL | 9.8 | Apr 30, 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions. |
| CVE-2020-12284 | CRITICAL | 9.8 | Apr 28, 2020 | cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check. |
| CVE-2019-20788 | CRITICAL | 9.8 | Apr 23, 2020 | libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690. |
| CVE-2020-11945 | CRITICAL | 9.8 | Apr 23, 2020 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials). |
| CVE-2019-12519 | CRITICAL | 9.8 | Apr 15, 2020 | An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow. |
| CVE-2019-12524 | CRITICAL | 9.8 | Apr 15, 2020 | An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resour |
| CVE-2020-6814 | CRITICAL | 9.8 | Mar 25, 2020 | Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6. |
| CVE-2020-10109 | CRITICAL | 9.8 | Mar 12, 2020 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request. |
| CVE-2020-10108 | CRITICAL | 9.8 | Mar 12, 2020 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request. |
| CVE-2020-6061 | CRITICAL | 9.8 | Feb 19, 2020 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability. |
| CVE-2020-8597 | CRITICAL | 9.8 | Feb 3, 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. |
| CVE-2019-17570 | CRITICAL | 9.8 | Jan 23, 2020 | An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed. |
Showing the 20 most severe of 2239 known CVEs.
Get Third Party Support