StackRadar

CVE-2025-38652

High

Advisory

Published 22 Aug 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
112
of 17,813 indexed, latest versions
Container images
119
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 112 of 17,813 indexed charts deploy, on 119 images.

Affected packageAffected versionsFixed inImages
linuxdeb4.15.0-38.41, 4.15.0-46.49, 4.15.0-50.54, 4.15.0-74.84+71 more5.15.0-163.173, 6.8.0-100.100119
OSV records
UBUNTU-CVE-2025-38652
Also known as
USN-7909-1, USN-8028-1

Charts affected

112 by stars
ChartLatestAffected imagesRadar Score
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
linux@4.15.0-46.49
no fix listed

Open the chart page →

93,130
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
linux@4.15.0-50.54
no fix listed

Open the chart page →

94,689
eg-edge-stackdatawire0.0.11 of 7See more

eg-edge-stack datawire 0.0.1

1 of the 7 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
linux@4.15.0-112.113
no fix listed

Open the chart page →

82,304
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
linux@5.4.0-152.169
no fix listed

Open the chart page →

76,789
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
5.15.0-163.173

Open the chart page →

116,089
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
5.15.0-163.173

Open the chart page →

115,089
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
6.8.0-100.100

Open the chart page →

92,708
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
linux@5.4.0-135.152
no fix listed

Open the chart page →

92,653
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
linux@5.4.0-144.161
no fix listed

Open the chart page →

72,876
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
linux@5.15.0-53.59
5.15.0-163.173

Open the chart page →

89,028
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
linux@5.4.0-216.236
no fix listed

Open the chart page →

113,143
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
linux@5.4.0-89.100
no fix listed

Open the chart page →

87,575
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
linux@5.4.0-80.90
no fix listed

Open the chart page →

100,981
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
6.8.0-100.100

Open the chart page →

83,510
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
linux@5.15.0-130.140
5.15.0-163.173

Open the chart page →

66,018
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
linux@5.4.0-200.220
no fix listed

Open the chart page →

77,057
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
linux@4.15.0-204.215
no fix listed

Open the chart page →

67,072
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
linux@5.4.0-189.209
no fix listed

Open the chart page →

73,884
httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
linux@5.4.0-135.152
no fix listed

Open the chart page →

76,124
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
linux@5.4.0-89.100
no fix listed

Open the chart page →

113,426
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
linux@5.4.0-131.147
no fix listed

Open the chart page →

76,149
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
linux@5.4.0-120.136
no fix listed

Open the chart page →

89,173
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
linux@5.4.0-131.147
no fix listed

Open the chart page →

76,149
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
linux@5.4.0-122.138
no fix listed

Open the chart page →

81,916
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
linux@5.15.0-133.144
5.15.0-163.173

Open the chart page →

61,974
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-100.100

Open the chart page →

67,567
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
linux@5.4.0-136.153
no fix listed

Open the chart page →

83,618
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
linux@4.15.0-204.215
no fix listed

Open the chart page →

68,898
kovi-appkovi-charts0.8.11 of 1See more

kovi-app kovi-charts 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
kennethreitz/httpbin:latest599fe5e50731
linux@4.15.0-38.41
no fix listed

Open the chart page →

85,956
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
linux@5.4.0-77.86
no fix listed

Open the chart page →

91,524
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
linux@5.15.0-130.140
5.15.0-163.173

Open the chart page →

63,775
allure_docker_servicelovemew67Verified publisher0.0.11 of 1See more

allure_docker_service lovemew67 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.27.00815040339a9
linux@4.15.0-213.224
no fix listed

Open the chart page →

65,433
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
linux@5.4.0-100.113
no fix listed

Open the chart page →

91,568
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
linux@4.15.0-191.202
no fix listed

Open the chart page →

72,154
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
linux@5.4.0-117.132
no fix listed

Open the chart page →

114,972
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
linux@5.4.0-90.101
no fix listed

Open the chart page →

101,376
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
linux@5.15.0-46.49
5.15.0-163.173

Open the chart page →

102,088
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
linux@5.15.0-46.49
5.15.0-163.173

Open the chart page →

102,088
smilencsaVerified publisher1.1.03 of 23See more

smile ncsa 1.1.0

3 of the 23 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
linux@5.4.0-163.180
no fix listed
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
linux@4.15.0-210.221
no fix listed
socialmediamacroscope/image_crawler:0.1.2f508216be63c
linux@4.15.0-210.221
no fix listed

Open the chart page →

279,307
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
linux@4.15.0-74.84
no fix listed

Open the chart page →

95,457
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
omecproject/mme-exporter:paging-latestbcc5f19fd676
linux@4.15.0-88.88
no fix listed

Open the chart page →

108,599
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
linux@4.15.0-126.129
no fix listed

Open the chart page →

81,512
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
linux@4.15.0-122.124
no fix listed

Open the chart page →

102,196
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
linux@5.4.0-125.141
no fix listed

Open the chart page →

92,617
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
linux@5.4.0-200.220
no fix listed

Open the chart page →

58,425
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
linux@5.4.0-200.220
no fix listed

Open the chart page →

58,366
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
linux@5.4.0-122.138
no fix listed

Open the chart page →

79,983
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
6.8.0-100.100

Open the chart page →

62,871
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
linux@5.4.0-117.132
no fix listed

Open the chart page →

101,945
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-38652.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
linux@4.15.0-191.202
no fix listed

Open the chart page →

66,239

Container images carrying it

119 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
twentycrm/twenty-postgres-spilo:latest2f78405a78be
linux@5.15.0-134.145
5.15.0-163.173
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
linux@4.15.0-204.215
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
linux@5.4.0-144.161
no fix listed
1
xeladock/mysql_dns:latest4baf531453f1
linux@5.15.0-25.25
5.15.0-163.173
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
linux@4.15.0-88.88
no fix listed
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
6.8.0-100.100
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
linux@5.4.0-110.124
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
linux@5.4.0-214.234
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
linux@5.4.0-80.90
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
linux@5.4.0-80.90
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-100.100
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
linux@5.4.0-121.137
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
linux@5.4.0-131.147
no fix listed
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
linux@5.4.0-200.220
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
linux@5.4.0-200.220
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
linux@4.15.0-191.202
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
linux@5.4.0-67.75
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.