Ubuntu 20.x — End of Life
EOL Actively exploitedUbuntu 20.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 20.10 | Oct 22, 2020 | Jul 22, 2021 | Jul 22, 2021 | 20.10 | EOL | |
| 20.04LTS | Apr 23, 2020 | Oct 1, 2022 | May 31, 2025 | 20.04.6 | EOL |
CVEs affecting Ubuntu 20.x (14)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-31431 | HIGH | 7.8 | 99.90% | KEV | 20.04 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla… | Apr 22, 2026 |
| CVE-2026-31431 | HIGH | 7.8 | 99.90% | KEV | 20.10 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla… | Apr 22, 2026 |
| CVE-2026-3888 | HIGH | 7.8 | 0.38% | — | 20.04 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private … | Mar 17, 2026 |
| CVE-2026-3497 | HIGH | 7.5 | 2.18% | — | 20.04 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI… | Mar 12, 2026 |
| CVE-2022-2586 | MEDIUM | 5.3 | 10.45% | KEV | 20.04 | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a… | Jan 8, 2024 |
| CVE-2022-1055 | HIGH | 7.8 | 0.50% | — | 20.04 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escala… | Mar 29, 2022 |
| CVE-2022-0492 | HIGH | 7.8 | 5.52% | KEV | 20.04 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th… | Mar 3, 2022 |
| CVE-2021-4034 | HIGH | 7.8 | 94.92% | KEV | 20.04 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool… | Jan 28, 2022 |
| CVE-2021-27364 | HIGH | 7.1 | 0.95% | — | 20.04 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by… | Mar 7, 2021 |
| CVE-2020-29372 | MEDIUM | 4.7 | 0.40% | — | 20.04 | An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition betwee… | Nov 28, 2020 |
| CVE-2020-13935 | HIGH | 7.5 | 86.60% | — | 20.04 | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to… | Jul 14, 2020 |
| CVE-2020-13934 | HIGH | 7.5 | 64.12% | — | 20.04 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release… | Jul 14, 2020 |
| CVE-2020-8619 | MEDIUM | 4.9 | 2.10% | — | 20.04 | In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edi… | Jun 17, 2020 |
| CVE-2020-9484 | HIGH | 7.0 | 56.63% | — | 20.04 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a)… | May 20, 2020 |
Ubuntu 20.x is EOL — migrate to Ubuntu 21.x
Ubuntu 21.x is the next major release. Plan your upgrade before Ubuntu 20.x stops receiving security patches.
Frequently asked questions
Is Ubuntu 20 end of life?
Yes. All Ubuntu 20.x releases have reached end of life and no longer receive security patches. There are 14 known CVEs affecting Ubuntu 20.x. Migrate to Ubuntu 21.x as soon as possible.
What CVEs affect Ubuntu 20?
There are 14 CVEs tracked for Ubuntu 20.x and 5 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Ubuntu 20 version?
The latest Ubuntu 20.x patch release is 20.10, released on October 22, 2020. Always run the latest patch to benefit from all security fixes.
How to migrate from Ubuntu 20 to Ubuntu 21?
To migrate from Ubuntu 20 to Ubuntu 21: (1) review the official Ubuntu 21 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Ubuntu 20 in production?
No. Ubuntu 20 has reached end of life and security vulnerabilities are no longer patched. Critically, 5 CVEs affecting Ubuntu 20.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
