Vulnerabilities on the latest kernel

45 views
Skip to first unread message

M4R1N

unread,
Jul 30, 2026, 4:55:53 PM (11 days ago) Jul 30
to Wazuh | Mailing List

Hello everyone. Could you please help us understand how Wazuh detects Linux kernel vulnerabilities?

We updated an Ubuntu 22.04.5 LTS server to the latest GA kernel available from the official repositories:

  • Current kernel: 5.15.0-186-generic

  • Package: linux-image-5.15.0-186-generic

  • Package version: 5.15.0-186.196

We also completely removed the previous kernel, rebooted the server, and confirmed that kernel 186 is the only kernel installed and running.

However, Wazuh still reports more than 2,000 vulnerabilities associated with the new kernel—almost the same number as before the update.

The findings contain the following value:

vulnerability.scanner.condition: Package default status

There is no explicit version comparison condition, such as “Package less than,” and no fixed version is shown.

Could you please clarify:

  1. What exactly does “Package default status” mean?

  2. Under this condition, does Wazuh compare the installed package version against a fixed version?

  3. Which Wazuh CTI source indicates that kernel package version 5.15.0-186.196 is affected?

  4. Is there any recommended configuration change, feed update, or synchronization procedure?

  5. Could these findings indicate an inconsistency or synchronization delay between Wazuh CTI and Canonical’s vulnerability data?

For example, we found CVEs reported by Wazuh for this package that Canonical classifies as “Not in release” for Ubuntu 22.04 Jammy.

We would like to understand whether any further action is required on the server or whether these findings should be treated as vulnerabilities without an available fix, non-applicable findings, or a possible CTI data inconsistency.

Jerwin Dula Capati

unread,
Jul 31, 2026, 12:28:20 AM (11 days ago) Jul 31
to Wazuh | Mailing List

Hi, thank you for providing the detailed information and for sharing the troubleshooting steps you've already performed.

Wazuh detects Linux kernel vulnerabilities by collecting the installed package inventory from the agent and correlating it with the Wazuh CTI database, which is built using information from official OS vendor security advisories, including Canonical for Ubuntu.

Regarding your questions:

  1. What does Package default status mean?
    This condition indicates that Wazuh relies on the vulnerability status provided by the OS vendor, rather than performing a direct comparison between the installed package version and a fixed version.

  2. Does Wazuh compare the installed package version against a fixed version under this condition?
    No. When the scanner condition is Package default status, the detection is based on the vendor's reported status for the package.

  1. Which Wazuh CTI source indicates that kernel package version 5.15.0-186.196 is affected?

  1. The information comes from the Wazuh CTI platform, which aggregates data from official vendor advisories. The exact mapping depends on the vulnerability data currently available in CTI.

  1. Is there any recommended configuration change, feed update, or synchronization procedure?

  1. No manual synchronization or configuration changes are normally required. Wazuh automatically keeps the CTI data up to date.

  2. Could this be an inconsistency between Wazuh CTI and Canonical's vulnerability data?
    If you observe CVEs that Canonical classifies as "Not in release" but are still reported by Wazuh, please share a few example CVEs with us. We can verify whether this behavior is expected based on the current CTI data or determine if it requires further review.

If you have any other questions or need further clarification, please let us know. We're happy to help.

Reply all
Reply to author
Forward
0 new messages