CVE-2026-0915
HighAdvisory
Published 15 Jan 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.006
- 48th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,571
- of 17,797 indexed, latest versions
- Container images
- 1,702
- deployed by those charts
- Fix available
- 3 of 4
- affected packages
CVE-2026-0915 affecting package glibc for versions less than 2.38-18
Carried by container images the latest versions of 1,571 of 17,797 indexed charts deploy, on 1,702 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| glibcdeb | 2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+49 more | 2.23-0ubuntu11.3+esm9, 2.27-3ubuntu1.6+esm6, 2.31-0ubuntu9.18+esm1, 2.35-0ubuntu3.13+4 more | 1,675 |
| glibcapk | 2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+6 more | 2.42-r6 | 19 |
| eglibcdeb | 2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 more | no fix listed | 7 |
| glibcrpm | 2.38-16.azl3 | 2.38-18 | 1 |
- OSV records
- CGA-9f7x-88h6-rvv4DEBIAN-CVE-2026-0915UBUNTU-CVE-2026-0915AZL-74633
- Also known as
- CGA-rm33-3ph7-88mp, USN-8005-1
Charts affected
1,571 by stars
Container images carrying it
1,702 by charts deploying them
A fixed version is listed for 3 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.k8s.io/ | 3e2bf2eaef9f | glibc | 2.36-9+deb12u14 | 1 |
| registry.k8s.io/ | ce5b5ccd5eb0 | glibc | 2.36-9+deb12u14 | 1 |