StackRadar

CVE-2023-4039

Medium

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,103
of 17,790 indexed, latest versions
Container images
1,152
deployed by those charts
Fix available
5 of 12
affected packages

Security update for gcc12

Carried by container images the latest versions of 1,103 of 17,790 indexed charts deploy, on 1,152 images.

Affected packageAffected versionsFixed inImages
gcc-12deb12-20220319-1ubuntu1, 12.1.0-2ubuntu1~22.04, 12.2.0-14, 12.3.0-1ubuntu1~22.0412.2.0-14+deb12u1, 12.3.0-1ubuntu1~22.04.2675
gcc-10deb10-20200411-0ubuntu1, 10.2.0-5ubuntu1~20.04, 10.3.0-1ubuntu1~20.04, 10.5.0-1ubuntu1~20.0410.5.0-1ubuntu1~20.04.1+esm1279
gcc-8deb8-20180414-1ubuntu2, 8.2.0-1ubuntu2~18.04, 8.3.0-6ubuntu1~18.04, 8.3.0-6ubuntu1~18.04.1+3 moreno fix listed120
gcc-5deb5.4.0-6ubuntu1~16.04.4, 5.4.0-6ubuntu1~16.04.5, 5.4.0-6ubuntu1~16.04.9, 5.4.0-6ubuntu1~16.04.10+2 moreno fix listed69
gccgo-6deb6.0.1-0ubuntu1no fix listed69
gcc-9deb9.3.0-17ubuntu1~20.04, 9.4.0-1ubuntu1~20.04.1, 9.4.0-1ubuntu1~20.04.2no fix listed45
gcc-7deb7.3.0-3ubuntu1, 7.3.0-27ubuntu1~18.04, 7.4.0-1ubuntu1~18.04, 7.4.0-1ubuntu1~18.04.1+2 moreno fix listed28
gcc-11deb11.2.0-19ubuntu1, 11.3.0-1ubuntu1~22.04, 11.3.0-12, 11.4.0-1ubuntu1~22.0411.4.0-1ubuntu1~22.04.214
gcc-4.8deb4.8.2-19ubuntu1, 4.8.4-2ubuntu1~14.04.3, 4.8.4-2ubuntu1~14.04.4no fix listed7
gccgo-4.9deb4.9.1-0ubuntu1, 4.9.3-0ubuntu4no fix listed7
gccapk13.1.0-r113.2.0-r31
gcc12rpm12.2.1+git416-150000.1.5.112.3.0+git1204-150000.1.16.11
OSV records
CGA-9fp5-8r38-hf7jDEBIAN-CVE-2023-4039UBUNTU-CVE-2023-4039SUSE-SU-2023:3661-1
Also known as
CGA-hg9x-wx5h-8pph, CGA-qp75-5rvw-vmvm, CGA-xfqf-q2hm-g3r5, USN-7700-1

Charts affected

1,103 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-4039.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
gcc-12@12.2.0-14
12.2.0-14+deb12u1
hamzaarshad10/querypodpy:1.7154f38e8668e
gcc-12@12.2.0-14
12.2.0-14+deb12u1
murtazashah46/helmfile:latest4d11726cf803
gcc-12@12.2.0-14
12.2.0-14+deb12u1

Open the chart page →

13,783
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-4039.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gcc-12@12.2.0-14
12.2.0-14+deb12u1

Open the chart page →

2,684
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2023-4039.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gcc-8@8.4.0-1ubuntu1~18.04
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gcc-10@10.3.0-1ubuntu1~20.04
10.5.0-1ubuntu1~20.04.1+esm1

Open the chart page →

9,256

Container images carrying it

1,152 by charts deploying them

A fixed version is listed for 5 of the 12 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
gcc-8@8.4.0-1ubuntu1~18.04
no fix listed
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
gcc-10@10.3.0-1ubuntu1~20.04
10.5.0-1ubuntu1~20.04.1+esm1
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
gcc-8@8.4.0-1ubuntu1~18.04
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
gcc-10@10.3.0-1ubuntu1~20.04
10.5.0-1ubuntu1~20.04.1+esm1
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
gcc-8@8.4.0-1ubuntu1~18.04
no fix listed
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
gcc-8@8.4.0-1ubuntu1~18.04
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
gcc-10@10.3.0-1ubuntu1~20.04
10.5.0-1ubuntu1~20.04.1+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
public.ecr.aws/zinclabs/openobserve:v0.8.127f8de509169
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
quay.io/aerokube/keygen:1.0.1578934444f04
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
gcc-12@12-20220319-1ubuntu1
12.3.0-1ubuntu1~22.04.2
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
gcc-12@12.3.0-1ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
gcc-8@8.4.0-1ubuntu1~18.04
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
gcc-12@12.1.0-2ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
gcc-12@12.1.0-2ubuntu1~22.04
12.3.0-1ubuntu1~22.04.2
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
gcc-5@5.4.0-6ubuntu1~16.04.12
gccgo-6@6.0.1-0ubuntu1
no fix listed
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
gcc-5@5.4.0-6ubuntu1~16.04.10
gccgo-6@6.0.1-0ubuntu1
no fix listed
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
gcc-10@10.2.0-5ubuntu1~20.04
gcc-9@9.3.0-17ubuntu1~20.04
10.5.0-1ubuntu1~20.04.1+esm1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
gcc-12@12.2.0-14
12.2.0-14+deb12u1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.