StackRadar

CVE-2025-14104

Medium

Advisory

Published 5 Dec 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,884
of 17,790 indexed, latest versions
Container images
2,046
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: util-linux security update

Carried by container images the latest versions of 1,884 of 17,790 indexed charts deploy, on 2,046 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:4.16.0-2+really2.41-5, 2.20.1-5.1ubuntu20.2+31 more2.41.3-1, 2.41.5-0+deb13u1+e11,630
util-linuxrpm2.32.1-8.el8, 2.32.1-17.el8, 2.32.1-22.el8, 2.32.1-24.el8+18 more0:2.32.1-48.el8_10, 0:2.37.4-21.el9, 0:2.37.4-21.el9_7, 2.40.4-150700.4.3.1+1 more313
util-linuxapk2.41-r9, 2.41.2-r02.41.4-r0, 2.41.6-r0103
OSV records
ALPINE-CVE-2025-14104DEBIAN-CVE-2025-14104RHSA-2026:1852RHSA-2026:1913RLSA-2026:1852RLSA-2026:1913UBUNTU-CVE-2025-14104ECHO-2993-d712-59ceopenSUSE-SU-2026:10072-1SUSE-SU-2026:0230-1

Charts affected

1,884 by stars
ChartLatestAffected imagesRadar Score
oesopsmxVerified publisher4.0.328 of 25See more

oes opsmx 4.0.32

8 of the 25 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
util-linux@2.27.1-6ubuntu3.6
no fix listed
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
util-linux@2.32.1-46.el8
0:2.32.1-48.el8_10
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
util-linux@2.32.1-46.el8
0:2.32.1-48.el8_10
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
util-linux@2.32.1-46.el8
0:2.32.1-48.el8_10
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
util-linux@2.41-5
2.41.3-1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
util-linux@2.32.1-27.el8
0:2.32.1-48.el8_10
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
util-linux@2.32.1-46.el8
0:2.32.1-48.el8_10
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
util-linux@2.32.1-46.el8
0:2.32.1-48.el8_10

Open the chart page →

108,315
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,344
redispascaliskeVerified publisher2.1.01 of 1See more

redis pascaliske 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/redis:8.0.3be0a135f1955
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,869
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
util-linux@2.32.1-43.el8
0:2.32.1-48.el8_10

Open the chart page →

2,994
prometheus-prefect-exporterprefectVerified publisher2026.8.71410241 of 1See more

prometheus-prefect-exporter prefect 2026.8.7141024

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
prefecthq/prometheus-prefect-exporter:4.0.050d527a190ae
util-linux@2.41-5
2.41.3-1

Open the chart page →

1,022
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,465
repoflowrepoflow-helm-public0.9.12 of 8See more

repoflow repoflow-helm-public 0.9.1

2 of the 8 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/elasticsearch:8.15.0310b9fc03b06
util-linux@2.34-0.1ubuntu9.6
no fix listed
library/postgres:16.24aea012537ed
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

13,647
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

8,783
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
util-linux@2.37.4-21.el9
0:2.37.4-21.el9_7

Open the chart page →

6,400
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

24,566
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
util-linux@2.37.4-21.el9
0:2.37.4-21.el9_7

Open the chart page →

860
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
util-linux@2.41-5
2.41.3-1

Open the chart page →

3,423
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
util-linux@2.41-5
2.41.3-1

Open the chart page →

5,926
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,377
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

15,564
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

7,075
pretixtechwolf12Verified publisher2026.7.03 of 3See more

pretix techwolf12 2026.7.0

3 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
util-linux@2.41-5
2.41.3-1
pretix/standalone:2026.7.05df3b7aa852e
util-linux@2.41-5
2.41.3-1
valkey/valkey:9.1.08e8d64b405ce
util-linux@2.41-5
2.41.3-1

Open the chart page →

9,894
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
util-linux@2.41-5
2.41.3-1

Open the chart page →

3,827
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

18,177
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

3,478
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
util-linux@2.32.1-28.el8
0:2.32.1-48.el8_10

Open the chart page →

6,085
wgerwgerOfficialVerified publisher1.0.03 of 8See more

wger wger 1.0.0

3 of the 8 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
util-linux@2.41-5
2.41.3-1
library/postgres:15.186eb0add3b77c
util-linux@2.41-5
2.41.3-1
library/redis:8.8.0234c902a2db4
util-linux@2.41-5
2.41.3-1

Open the chart page →

8,634
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
util-linux@2.32.1-28.el8
0:2.32.1-48.el8_10

Open the chart page →

4,713
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
util-linux@2.41-5
2.41.3-1

Open the chart page →

4,651
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
util-linux@2.37.4-21.el9
0:2.37.4-21.el9_7

Open the chart page →

1,851
paperless-ngxadnoctemVerified publisher0.4.22 of 5See more

paperless-ngx adnoctem 0.4.2

2 of the 5 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
util-linux@2.41-5
2.41.3-1
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
util-linux@2.41-5
2.41.3-1

Open the chart page →

19,828
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

13,671
agentareaagentareaVerified publisher0.0.184 of 16See more

agentarea agentarea 0.0.18

4 of the 16 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
agentarea/agentarea-api:latest9e15e16fa758
util-linux@2.41-5
2.41.3-1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
util-linux@2.38.1-5+deb12u3
no fix listed
agentarea/agentarea-worker:latest1e5cb68ee77a
util-linux@2.41-5
2.41.3-1
valkey/valkey:9.0.1546304417fea
util-linux@2.41-5
2.41.3-1

Open the chart page →

15,049
jellyfinalekcVerified publisher0.9.01 of 1See more

jellyfin alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
util-linux@2.41-5
2.41.3-1

Open the chart page →

2,626
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.02 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

2 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
util-linux@2.41-5
2.41.3-1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
util-linux@2.41-5
2.41.3-1

Open the chart page →

12,092
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

12,081
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
util-linux@2.41-5
2.41.3-1

Open the chart page →

5,971
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

3,395
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
util-linux@2.38.1-5+b1
no fix listed
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

22,304
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,249
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,736
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
util-linux@2.41-5
2.41.3-1

Open the chart page →

2,327
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
util-linux@2.34-0.1ubuntu9.4
no fix listed

Open the chart page →

17,951
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
util-linux@2.27.1-6ubuntu3.4
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

77,883
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
util-linux@2.27.1-6ubuntu3.4
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

77,863
astradnsastradnsVerified publisher0.2.91 of 2See more

astradns astradns 0.2.9

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,649
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

13,219
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

2,919
brightdata-exporterbrightdata-chartsVerified publisher0.2.171 of 1See more

brightdata-exporter brightdata-charts 0.2.17

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
util-linux@2.41-5
2.41.3-1

Open the chart page →

1,306
pgvectorcagriekinVerified publisher2.1.01 of 3See more

pgvector cagriekin 2.1.0

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
util-linux@2.41-5
2.41.3-1

Open the chart page →

4,056
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

84,710
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
util-linux@2.34-0.1ubuntu9.1
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

84,710
carbone-eecarboneOfficialVerified publisher1.0.61 of 1See more

carbone-ee carbone 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
carbone/carbone-ee:full-5.11.0518172cbad49
util-linux@2.41-5
2.41.3-1

Open the chart page →

1,641
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

16,056
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
util-linux@2.41-5
2.41.3-1

Open the chart page →

2,383

Container images carrying it

2,046 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dakera-ai/dakera-mcp:0.10.11a3d48418b14a
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
util-linux@2.41-5
2.41.3-1
1
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
util-linux@2.41-5
2.41.3-1
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
util-linux@2.41-5
2.41.3-1
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
util-linux@2.41-5
2.41.3-1
1
ghcr.io/dask/dask:2024.1.0080150de7d86
util-linux@2.34-0.1ubuntu9.4
no fix listed
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
util-linux@2.41-5
2.41.3-1
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
util-linux@2.34-0.1ubuntu9.3
no fix listed
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
util-linux@2.41-5
2.41.3-1
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
util-linux@2.41-5
2.41.3-1
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
util-linux@2.37.4-21.el9
0:2.37.4-21.el9_7
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
util-linux@2.41-5
2.41.3-1
1
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.3:latestecacd9fd0c66
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.5f69554198005
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/drakkan/sftpgo:v2.7.46cb60f08fede
util-linux@2.41-5
2.41.3-1
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
util-linux@2.38.1-5+b1
no fix listed
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
util-linux@2.38.1-5+b1
no fix listed
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
util-linux@2.32.1-28.el8
0:2.32.1-48.el8_10
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
util-linux@2.32.1-28.el8
0:2.32.1-48.el8_10
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
util-linux@2.32.1-38.el8
0:2.32.1-48.el8_10
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
util-linux@2.37.4-9.el9
0:2.37.4-21.el9_7
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
util-linux@2.34-0.1ubuntu9.3
no fix listed
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
util-linux@2.41-5
2.41.3-1
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
util-linux@2.38.1-5+deb12u1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
util-linux@2.41-5
2.41.3-1
1
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
util-linux@2.41-5
2.41.3-1
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
util-linux@2.41-5
2.41.3-1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.