CVE-2024-40902
HighAdvisory
Published 12 Jul 2024In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 127
- of 17,803 indexed, latest versions
- Container images
- 128
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 127 of 17,803 indexed charts deploy, on 128 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| linuxdeb | 3.13.0-46.77, 3.13.0-126.175, 3.13.0-149.199, 3.13.0-170.220+70 more | 4.4.0-259.293, 4.15.0-229.241, 5.4.0-195.215, 5.15.0-121.131+1 more | 128 |
- OSV records
- UBUNTU-CVE-2024-40902
- Also known as
- USN-6999-1, USN-7003-1, USN-7007-1, USN-7028-1, USN-7039-1
Charts affected
127 by stars
Container images carrying it
128 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| oomk8s/ | 875814cc853d | linux | 4.4.0-259.293 | 11 |
| oomk8s/ | 7daa08b81954 | linux | 4.4.0-259.293 | 6 |
| hyperledger/ | 4ce6f43ded2e | linux | 4.4.0-259.293 | 4 |
| hyperledger/ | f6c724592abf | linux | 4.4.0-259.293 | 4 |
| istio/ | dbb7726d1bf0 | linux | 4.15.0-229.241 | 2 |
| istio/ | a78b7a165744 | linux | 4.15.0-229.241 | 2 |
| omecproject/ | cfdb566dd949 | linux | 4.4.0-259.293 | 2 |
| smartedge/ | 4cd63c22ce36 | linux | 5.4.0-195.215 | 2 |
| streamnative/ | 0e6d7aa3ef32 | linux | 5.4.0-195.215 | 2 |
| ghcr.io/ | 5be52524664c | linux | 5.15.0-121.131 | 2 |
| ghcr.io/ | 5f545698e907 | linux | 5.15.0-121.131 | 2 |
| ghcr.io/ | 103fbcec2314 | linux | 5.4.0-195.215 | 2 |
| ghcr.io/ | 4ee0764310e7 | linux | 4.15.0-229.241 | 2 |
| a10networks/ | 8dc58d434d71 | linux | 4.15.0-229.241 | 1 |
| allegroai/ | 772827a01bb5 | linux | 4.15.0-229.241 | 1 |
| apachepulsar/ | d056c89b7131 | linux | 5.4.0-195.215 | 1 |
| apachepulsar/ | d538416d5afe | linux | 5.4.0-195.215 | 1 |
| assistiot/ | 30812ba93555 | linux | 5.15.0-121.131 | 1 |
| assistiot/ | e5ae539ce2cb | linux | 5.4.0-195.215 | 1 |
| bicarus/ | b1dab0721e1c | linux | 5.4.0-195.215 | 1 |
| browserless/ | c81ae5585b47 | linux | 5.4.0-195.215 | 1 |
| chetangautamm/ | b4b94155ff5a | linux | no fix listed | 1 |
| chetangautamm/ | e7f7049e1544 | linux | 5.4.0-195.215 | 1 |
| cheyang/ | 46cc34755493 | linux | 4.4.0-259.293 | 1 |
| cloudve/ | af56e77ca587 | linux | 4.15.0-229.241 | 1 |
| countly/ | e3c238248f99 | linux | 5.4.0-195.215 | 1 |
| dgraziotin/ | 38f2de42bed0 | linux | 5.4.0-195.215 | 1 |
| ethereumex/ | a7603aa8df4c | linux | 4.4.0-259.293 | 1 |
| flyway/ | 45b5d7cdc75a | linux | 5.4.0-195.215 | 1 |
| frankescobar/ | 8a4d7e9308de | linux | 4.15.0-229.241 | 1 |
| frankescobar/ | cafa03b94dac | linux | 4.15.0-229.241 | 1 |
| galaxy/ | 0267bad550e6 | linux | no fix listed | 1 |
| galaxy/ | 8e577a626dfd | linux | no fix listed | 1 |
| geoscienceaustralia/ | f4039b45572a | linux | 4.15.0-229.241 | 1 |
| gethue/ | 11b649636e68 | linux | 5.4.0-195.215 | 1 |
| gethue/ | 5702b2c37ff9 | linux | 4.15.0-229.241 | 1 |
| grpl/ | c00aafee6629 | linux | 6.8.0-44.44 | 1 |
| haveagitgat/ | 1256348872ce | linux | 5.4.0-195.215 | 1 |
| haveagitgat/ | 3ff0913202dd | linux | 5.4.0-195.215 | 1 |
| huginn/ | c794eddc7b47 | linux | 4.15.0-229.241 | 1 |
| hyperledger/ | c65891b6c237 | linux | 4.4.0-259.293 | 1 |
| ibmcom/ | b5d8c6714dbc | linux | 4.4.0-259.293 | 1 |
| ibmcom/ | e17bdccc5030 | linux | 4.4.0-259.293 | 1 |
| intel/ | aa8f5483a2ef | linux | 5.4.0-195.215 | 1 |
| intel/ | 1a89327e499b | linux | 5.4.0-195.215 | 1 |
| ironmansoftware/ | 1943c73cce31 | linux | 5.4.0-195.215 | 1 |
| istio/ | 2232f365aed6 | linux | 4.15.0-229.241 | 1 |
| istio/ | 268ab879ea51 | linux | 4.4.0-259.293 | 1 |
| istio/ | 655eefa11c84 | linux | 4.15.0-229.241 | 1 |
| istio/ | 294ca55bd1cc | linux | 4.15.0-229.241 | 1 |