USN
Ubuntu Security Notice
Ubuntu-Sicherheitshinweis
A USN is Canonical's official security notice for vulnerabilities in Ubuntu. It names the affected packages, the associated Common Vulnerabilities and Exposures (CVE)-IDs and the version in which the flaw is closed. For Ubuntu systems the USN is the authoritative source for the actual patch status.
History & facts. USN identifiers carry the format USN-NUMBER-REVISION. As with Debian and Red Hat, the USN exists because the generic Common Vulnerabilities and Exposures (CVE) does not answer whether a flaw is fixed in a concrete Ubuntu release and package version. Canonical maintains a security team and open CVE tracking for this, indicating the status per supported release.
Outlook & recommendation. In automated patch and vulnerability management, distribution advisories such as USN, Debian Security Advisory (DSA) and Red Hat Security Advisory (RHSA) are the precise bridge between a Common Vulnerabilities and Exposures (CVE) and the question „fixed or not“. Threat-intelligence platforms normalise these sources against the underlying CVEs to produce, per system, an unambiguous, duplicate-free statement of exposure.