StackRadar

CVE-2025-14104

Medium

Advisory

Published 5 Dec 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,910
of 17,828 indexed, latest versions
Container images
2,041
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: util-linux security update

Carried by container images the latest versions of 1,910 of 17,828 indexed charts deploy, on 2,041 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:4.16.0-2+really2.41-5, 2.20.1-5.1ubuntu20.2+31 more2.41.3-1, 2.41.5-0+deb13u1+e11,640
util-linuxrpm2.32.1-8.el8, 2.32.1-17.el8, 2.32.1-22.el8, 2.32.1-24.el8+19 more0:2.32.1-48.el8_10, 0:2.37.4-21.el9, 0:2.37.4-21.el9_7, 2.40.4-150700.4.3.1+1 more297
util-linuxapk2.41-r9, 2.41.2-r02.41.4-r0, 2.41.6-r0104
OSV records
ALPINE-CVE-2025-14104DEBIAN-CVE-2025-14104RHSA-2026:1852RHSA-2026:1913RLSA-2026:1852RLSA-2026:1913UBUNTU-CVE-2025-14104ECHO-2993-d712-59ceopenSUSE-SU-2026:10072-1SUSE-SU-2026:0230-1

Charts affected

1,910 by stars
ChartLatestAffected imagesRadar Score
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
util-linux@2.41-5
2.41.3-1

Open the chart page →

1,254
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

11,521
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
util-linux@2.38.1-5+deb12u3
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
util-linux@2.41-5
2.41.3-1

Open the chart page →

7,118
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,957
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

4,360
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

6,551
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
util-linux@2.38.1-5+deb12u3
no fix listed
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

7,732
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,091
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
util-linux@2.34-0.1ubuntu9.4
no fix listed

Open the chart page →

12,948
litellm-helmlitellm1.102.01 of 2See more

litellm-helm litellm 1.102.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

5,106
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
util-linux@2.41-5
2.41.3-1

Open the chart page →

2,192
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
util-linux@2.41-5
2.41.3-1

Open the chart page →

10,276
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
util-linux@2.41-5
2.41.3-1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,614
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

81,519
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

7,943
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
util-linux@2.32.1-27.el8
0:2.32.1-48.el8_10

Open the chart page →

6,859
glasskube-operatorglasskubeOfficialVerified publisher0.12.22 of 3See more

glasskube-operator glasskube 0.12.2

2 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
util-linux@2.32.1-42.el8_8
0:2.32.1-48.el8_10
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
util-linux@2.32.1-42.el8_8
0:2.32.1-48.el8_10

Open the chart page →

12,208
kube-prometheus-stackkube-prometheus-stack-oci91.4.11 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 91.4.1

1 of the 6 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

682
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,348
plane-cemakeplaneOfficialVerified publisher1.8.11 of 11See more

plane-ce makeplane 1.8.1

1 of the 11 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
valkey/valkey:7.2.11-alpine10328d00120d
util-linux@2.41.2-r0
2.41.4-r0

Open the chart page →

5,004
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

5,545
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
util-linux@2.37.4-21.el9
0:2.37.4-21.el9_7

Open the chart page →

6,435
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

87,176
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
util-linux@2.32.1-43.el8
0:2.32.1-48.el8_10

Open the chart page →

6,684
codefreshcodefresh-onpremOfficialVerified publisher2.12.164See more

codefresh codefresh-onprem 2.12.16

4 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
util-linux@2.38.1-5+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
util-linux@2.38.1-5+deb12u3
no fix listed
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

velero-uiotwldVerified publisher0.16.01 of 1See more

velero-ui otwld 0.16.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.31c228d9ef71b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,391
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2api:3.86f56d239d280
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2auth:3.833ecfda16608
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2notifier:3.8f190a6212195
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2web:3.809989a26c8b7
util-linux@2.34-0.1ubuntu9.4
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
util-linux@2.34-0.1ubuntu9.4
no fix listed

Open the chart page →

740,653
supabasetokens-studioVerified publisher1.0.04 of 14See more

supabase tokens-studio 1.0.0

4 of the 14 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
supabase/edge-runtime:v1.59.0eff9c554d649
util-linux@2.38.1-5+deb12u1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
util-linux@2.38.1-5+deb12u1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
util-linux@2.38.1-5+deb12u1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

22,872
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
util-linux@2.38.1-5+deb12u1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

8,473
budibasebudibase0.0.0-master2 of 7See more

budibase budibase 0.0.0-master

2 of the 7 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
util-linux@2.38.1-5+deb12u3
no fix listed
budibase/proxy:3.41.38d780b6ee602
util-linux@2.41-5
2.41.3-1

Open the chart page →

9,471
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,853
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

1,114
paperless-ngxfmjstudios0.2.82 of 5See more

paperless-ngx fmjstudios 0.2.8

2 of the 5 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
util-linux@2.38.1-5+b1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

31,321
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,002
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
util-linux@2.32.1-28.el8
0:2.32.1-48.el8_10

Open the chart page →

4,417
quickwitquickwit0.8.171 of 1See more

quickwit quickwit 0.8.17

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

3,453
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

11,643
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
util-linux@2.41-5
2.41.3-1

Open the chart page →

2,935
connaisseurconnaisseurVerified publisher2.13.01 of 2See more

connaisseur connaisseur 2.13.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,880
devtron-operatordevtron0.23.32 of 11See more

devtron-operator devtron 0.23.3

2 of the 11 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
util-linux@2.38.1-5+b1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

33,425
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/postgresql:16233f361c5819
util-linux@2.38.1-5+deb12u2
no fix listed
ilum/api:6.7.3624fd09528c8
util-linux@2.41-5
2.41.3-1
ilum/marquez:0.54.06e1d709d41f8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

22,408
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
util-linux@2.41-5
2.41.3-1

Open the chart page →

1,859
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

7,300
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
util-linux@2.41-5
2.41.3-1

Open the chart page →

5,705
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
util-linux@2.41-5
2.41.3-1

Open the chart page →

4,453
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
util-linux@2.34-0.1ubuntu9.6
no fix listed
netrisai/controller-telescope:4.6.0.00414d82948a8b2
util-linux@2.34-0.1ubuntu9.6
no fix listed
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
util-linux@2.34-0.1ubuntu9.6
no fix listed
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
util-linux@2.41.2-r0
2.41.4-r0
netrisai/controller-web-session-generator:0.2.0a030a31289f4
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

30,605
hedgedocnicholaswildeVerified publisher1.1.01 of 1See more

hedgedoc nicholaswilde 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

12,717
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
util-linux@2.41-5
2.41.3-1

Open the chart page →

2,336
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

17,443
paperless-ngxpaperless-ngxVerified publisher0.3.222 of 3See more

paperless-ngx paperless-ngx 0.3.22

2 of the 3 container images this version deploys carry CVE-2025-14104.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
util-linux@2.38.1-5+deb12u3
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
util-linux@2.41-5
2.41.3-1

Open the chart page →

8,593

Container images carrying it

2,041 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

No deployed image carries CVE-2025-14104.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.