CVE-2026-32282
MediumAdvisory
Published 7 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.4
- base score, highest
- EPSS
- 0.003
- 22nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,917
- of 17,805 indexed, latest versions
- Container images
- 4,443
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
Carried by container images the latest versions of 3,917 of 17,805 indexed charts deploy, on 4,443 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+178 more | 1.25.9 | 4,443 |
- OSV records
- DEBIAN-CVE-2026-32282GO-2026-4864
- Also known as
- BIT-golang-2026-32282
Charts affected
3,917 by stars
Container images carrying it
4,443 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| prom/ | 632f70580492 | stdlib | 1.25.9 | 1 |
| prom/ | 8be660470961 | stdlib | 1.25.9 | 1 |
| promzeus/ | 82f6d56e280b | stdlib | 1.25.9 | 1 |
| pschiffe/ | 37ebba8c2b8f | stdlib | 1.25.9 | 1 |
| pschiffe/ | d196c796cafb | stdlib | 1.25.9 | 1 |
| pschiffe/ | a227d41bc665 | stdlib | 1.25.9 | 1 |
| pubeldev/ | 1091665a020a | stdlib | 1.25.9 | 1 |
| pulumi/ | 7dace4491358 | stdlib | 1.25.9 | 1 |
| pysga1996/ | 3af6d0c7db19 | stdlib | 1.25.9 | 1 |
| qichenxu4pd/ | d758d41d9c6b | stdlib | 1.25.9 | 1 |
| qmcgaw/ | 1a5bf4b4820a | stdlib | 1.25.9 | 1 |
| qmcgaw/ | 2b42bfa04675 | stdlib | 1.25.9 | 1 |
| qonstrukt/ | 089af7925aa1 | stdlib | 1.25.9 | 1 |
| qoveryrd/ | b30a9398a83c | stdlib | 1.25.9 | 1 |
| quiq/ | 91281da47036 | stdlib | 1.25.9 | 1 |
| qumine/ | f2c8a2148381 | stdlib | 1.25.9 | 1 |
| qumine/ | c0b650d51132 | stdlib | 1.25.9 | 1 |
| rabbitmqoperator/ | 231e7ce0e905 | stdlib | 1.25.9 | 1 |
| rabbitmqoperator/ | 840be4bad78e | stdlib | 1.25.9 | 1 |
| rabbitmqoperator/ | 8651dd3cec51 | stdlib | 1.25.9 | 1 |
| rahulbhiwagade122/ | 08490b70998c | stdlib | 1.25.9 | 1 |
| ralexstokes/ | c0d4bbefd31f | stdlib | 1.25.9 | 1 |
| rancher/ | 8c2599ecfca8 | stdlib | 1.25.9 | 1 |
| rancher/ | eaa270df79cc | stdlib | 1.25.9 | 1 |
| rancher/ | 85a0d1148784 | stdlib | 1.25.9 | 1 |
| rancher/ | 9289da488b07 | stdlib | 1.25.9 | 1 |
| rancher/ | 9b9148811700 | stdlib | 1.25.9 | 1 |
| rancher/ | d5999b20a1b1 | stdlib | 1.25.9 | 1 |
| rancher/ | e34c88ae0aff | stdlib | 1.25.9 | 1 |
| rancher/ | febfd0517838 | stdlib | 1.25.9 | 1 |
| rancher/ | 6cbc1e932b5b | stdlib | 1.25.9 | 1 |
| rancher/ | a41cd716c412 | stdlib | 1.25.9 | 1 |
| rancher/ | 3126395b966c | stdlib | 1.25.9 | 1 |
| rancher/ | 34fa058fe453 | stdlib | 1.25.9 | 1 |
| rancher/ | 9813f85653c8 | stdlib | 1.25.9 | 1 |
| raspbernetes/ | a552705225fd | stdlib | 1.25.9 | 1 |
| rayselfs/ | 562e5b2f81ce | stdlib | 1.25.9 | 1 |
| rclone/ | 08e1af3c8814 | stdlib | 1.25.9 | 1 |
| rclone/ | 1e6eeabddc01 | stdlib | 1.25.9 | 1 |
| rclone/ | f2fc45c8bc57 | stdlib | 1.25.9 | 1 |
| reallibrephotos/ | 58cdf5e93471 | stdlib | 1.25.9 | 1 |
| reaper99/ | 7f7ec3aeb88c | stdlib | 1.25.9 | 1 |
| redislabs/ | 9078e713bb6a | stdlib | 1.25.9 | 1 |
| redislabs/ | 33561794c5c8 | stdlib | 1.25.9 | 1 |
| redpandadata/ | c05fa976428e | stdlib | 1.25.9 | 1 |
| regclient/ | 3d8d8e40afb7 | stdlib | 1.25.9 | 1 |
| replicated/ | 8751b4963250 | stdlib | 1.25.9 | 1 |
| reportportal/ | 464468240d7b | stdlib | 1.25.9 | 1 |
| reportportal/ | da5d8e1395fe | stdlib | 1.25.9 | 1 |
| reportportal/ | 2b27a2d7a87d | stdlib | 1.25.9 | 1 |