ghcr.io/linuxserver/booksonic-air:version-v2009.1.0 container image
GitHub Container RegistryScanned 15 Sept 2026
Deployed by 1 of 17,787 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/linuxserver/booksonic-air
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0 resolved to baa4fa9549dc, scanned 15 Sept 2026: 1,177 findings, 21 critical, 10 on KEV; deployed by 1 chart, among them booksonic-air.
Radar Score
1,177 findings on digest baa4fa9549dc · scanned 15 Sept 2026
KEV ×10 confirmed exploitedRadar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
Findings for digest baa4fa9549dc as scanned on 15 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 15 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-87875 | cups | no fix listed |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | 0.23.9-2ubuntu0.1+esm1 |
| Low | UBUNTU-CVE-2026-0989 | libxml2 | 2.9.4+dfsg1-6.1ubuntu1.9+esm7 |
| Low | GHSA-wf8f-6423-gfxg | jackson-core | 2.13.0 |
| Low | UBUNTU-CVE-2026-21925 | openjdk-8 | 8u482-ga~us1-0ubuntu1~18.04 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-22795 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm7 |
| Low | UBUNTU-CVE-2025-3360 | glib2.0 | 2.56.4-0ubuntu0.18.04.9+esm5 |
| Low | UBUNTU-CVE-2026-41254 | lcms2 | 2.9-1ubuntu0.1+esm1 |
| Low | UBUNTU-CVE-2025-8114 | libssh | 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm5 |
| Low | UBUNTU-CVE-2026-1484 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2026-75145 | ffmpeg | no fix listed |
| Low | UBUNTU-CVE-2026-54370 | acl | no fix listed |
| Low | UBUNTU-CVE-2026-56412 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-70631 | ffmpeg | no fix listed |
| Low | UBUNTU-CVE-2026-4367 | libxpm | no fix listed |
| Low | UBUNTU-CVE-2026-70629 | ffmpeg | no fix listed |
| Low | UBUNTU-CVE-2026-70630 | ffmpeg | no fix listed |
| Low | UBUNTU-CVE-2021-36086 | libsepol | 2.7-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-56131 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-50219 | expat | no fix listed |
| Low | UBUNTU-CVE-2025-15649 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-23865 | openjdk-8 | 8u492-ga~us2-0ubuntu1~18.04.1 |
| Low | UBUNTU-CVE-2026-0988 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2025-7039 | glib2.0 | 2.56.4-0ubuntu0.18.04.9+esm5 |
| Low | UBUNTU-CVE-2024-56433 | shadow | no fix listed |
| Low | UBUNTU-CVE-2026-41991 | gzip | no fix listed |
| Low | UBUNTU-CVE-2026-23868 | giflib | no fix listed |
| Low | UBUNTU-CVE-2026-40226 | systemd | no fix listed |
| Low | UBUNTU-CVE-2025-61143 | tiff | 4.0.9-5ubuntu0.10+esm10 |
| Low | UBUNTU-CVE-2025-4877 | libssh | 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4 |
| Low | UBUNTU-CVE-2026-89092 | glibc | no fix listed |
| Low | GHSA-9m89-8frq-c98c | tomcat-embed-core | 9.0.118 |
| Low | UBUNTU-CVE-2026-18374 | glibc | no fix listed |
| Low | UBUNTU-CVE-2021-36084 | libsepol | 2.7-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-86469 | glib2.0 | no fix listed |
| Low | UBUNTU-CVE-2025-69277 | libsodium | no fix listed |
| Low | UBUNTU-CVE-2023-38288 | tiff | 4.0.9-5ubuntu0.10+esm2 |
| Low | UBUNTU-CVE-2023-38289 | tiff | 4.0.9-5ubuntu0.10+esm2 |
| Low | UBUNTU-CVE-2026-19542 | glibc | no fix listed |
| Low | UBUNTU-CVE-2026-36849 | tiff | no fix listed |
| Low | UBUNTU-CVE-2026-53613 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-53615 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-61626 | libass | no fix listed |
| Low | UBUNTU-CVE-2026-61627 | libass | no fix listed |
| Low | UBUNTU-CVE-2026-77117 | glibc | no fix listed |
| Low | UBUNTU-CVE-2026-80489 | glibc | no fix listed |
| Low | UBUNTU-CVE-2021-36085 | libsepol | 2.7-1ubuntu0.1 |
| Low | UBUNTU-CVE-2021-36087 | libsepol | 2.7-1ubuntu0.1 |
| Low | UBUNTU-CVE-2025-68160 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm7 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| booksonic-airgeek-cookbookVerified publisher | 6.4.2 | version-v2009.1.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.