Ubuntu 20.04 'Focal Fossa' (LTS)
Ubuntu 20.04 'Focal Fossa' (LTS)
Third-party support for the Ubuntu 20.04 'Focal Fossa' (LTS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Ubuntu 20.04 'Focal Fossa' (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- ubuntu
- release
- 20.04
- product Label
- Ubuntu
- release Label
- 20.04 'Focal Fossa' (LTS)
- codename
- Focal Fossa
- lts
- true
- latest Version
- 20.04.6
- release Date
- 2020-04-23
- maintained
- true
- source Url
- https://endoflife.date/ubuntu
Lifecycle Dates
- End of Service Life
- Apr 2, 2030
- Last OEM Support
- Oct 1, 2022
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Ubuntu 20.04 'Focal Fossa' (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Ubuntu 20.04 'Focal Fossa' (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Ubuntu 20.04 'Focal Fossa' (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Ubuntu 20.04 'Focal Fossa' (LTS) Support: Frequently Asked Questions
Is the Ubuntu 20.04 'Focal Fossa' (LTS) still supported?
Yes. The Ubuntu 20.04 'Focal Fossa' (LTS) is currently supported by Ubuntu, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Ubuntu 20.04 'Focal Fossa' (LTS) end of service life (EOSL) date?
Ubuntu lists the end of service life for the Ubuntu 20.04 'Focal Fossa' (LTS) as Apr 2, 2030.
Can I keep using the Ubuntu 20.04 'Focal Fossa' (LTS) after its EOSL date?
Yes. EOSL means Ubuntu stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Ubuntu 20.04 'Focal Fossa' (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Ubuntu 20.04 'Focal Fossa' (LTS)
446 published CVEs affect the Ubuntu 20.04 'Focal Fossa' (LTS), including 178 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2023-1523 | CRITICAL | 10.0 | Sep 1, 2023 | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console. |
| CVE-2020-13753 | CRITICAL | 10.0 | Jul 14, 2020 | The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226. |
| CVE-2022-1736 | CRITICAL | 9.8 | Jan 31, 2025 | Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default. |
| CVE-2020-11984 | CRITICAL | 9.8 | Aug 7, 2020 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
| CVE-2020-15900 | CRITICAL | 9.8 | Jul 28, 2020 | A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b. |
| CVE-2020-14001 | CRITICAL | 9.8 | Jul 17, 2020 | The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. |
| CVE-2017-18922 | CRITICAL | 9.8 | Jun 30, 2020 | It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow. |
| CVE-2020-6831 | CRITICAL | 9.8 | May 26, 2020 | A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. |
| CVE-2020-12395 | CRITICAL | 9.8 | May 26, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. |
| CVE-2020-12284 | CRITICAL | 9.8 | Apr 28, 2020 | cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check. |
| CVE-2020-11945 | CRITICAL | 9.8 | Apr 23, 2020 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials). |
| CVE-2019-12519 | CRITICAL | 9.8 | Apr 15, 2020 | An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow. |
| CVE-2020-6061 | CRITICAL | 9.8 | Feb 19, 2020 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability. |
| CVE-2019-19948 | CRITICAL | 9.8 | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. |
| CVE-2019-17542 | CRITICAL | 9.8 | Oct 14, 2019 | FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c. |
| CVE-2019-17539 | CRITICAL | 9.8 | Oct 14, 2019 | In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer. |
| CVE-2019-17455 | CRITICAL | 9.8 | Oct 10, 2019 | Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request. |
| CVE-2005-1513 | CRITICAL | 9.8 | May 11, 2005 | Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request. |
| CVE-2020-27352 | CRITICAL | 9.3 | Jun 21, 2024 | When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended. |
| CVE-2020-15708 | CRITICAL | 9.3 | Nov 6, 2020 | Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code. |
Showing the 20 most severe of 446 known CVEs.
Get Third Party Support