StackRadar

CVE-2026-76642

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,738
of 17,828 indexed, latest versions
Container images
2,748
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-76642 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,738 of 17,828 indexed charts deploy, on 2,748 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,488
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r0, 2.42.3-r0259
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-76642DEBIAN-CVE-2026-76642UBUNTU-CVE-2026-76642AZL-99081ECHO-b20e-705a-6d36

Charts affected

2,738 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,748 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
util-linux@2.34-0.1ubuntu9.1
no fix listed
3
codeurjc/planner:v1.0800cf520c245
util-linux@2.37.2-4ubuntu3
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
util-linux@2.34-0.1ubuntu9.1
no fix listed
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
util-linux@2.38.1-5+deb12u1
no fix listed
3
dpage/pgadmin4:9.17:latest2f4ce946ddf8
util-linux@2.42.1-r0
2.42.3-r0
3
emberstack/kubernetes-reflector:10.0.6551dbd5880929
util-linux@2.39.3-9ubuntu6.5
no fix listed
3
envoyproxy/envoy:v1.31.02bf7f042e396
util-linux@2.37.2-4ubuntu3.4
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
util-linux@2.39.3-9ubuntu6
no fix listed
3
guacamole/guacamole:1.6.0f344085e618b
util-linux@2.39.3-9ubuntu6.2
no fix listed
3
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
util-linux@2.42.1-r0
2.42.3-r0
3
istio/kubectl:1.5.10dbb7726d1bf0
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
3
jacobalberty/unifi:v10.0.162896c0ab82d33
util-linux@2.34-0.1ubuntu9.6
no fix listed
3
library/memcached:1.6:1.6.4575c93cc91e76
util-linux@2.41.5-0+deb13u1
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
util-linux@2.38.1-5+deb12u1
no fix listed
3
library/nginx:1.30.4-alpine3.24:stable-alpinedc5069ad14f1
util-linux@2.42.1-r0
2.42.3-r0
3
library/node:lts64af3819f927
util-linux@2.38.1-5+deb12u3
no fix listed
3
library/postgres:15-alpinefe0737ba566a
util-linux@2.42.1-r0
2.42.3-r0
3
library/ubuntu:24.04008173c23f95
util-linux@2.39.3-9ubuntu6.6
no fix listed
3
library/ubuntu:latest2260313b31c8
util-linux@2.41.3-3ubuntu2
no fix listed
3
library/ubuntu:latestda6fc2be5478
util-linux@2.41.3-3ubuntu2.2
no fix listed
3
linuxserver/plex:1.43.4:latest1f6f97d76e7b
util-linux@2.41.3-3ubuntu2.2
no fix listed
3
localstack/localstack:latest4abc29e923e5
util-linux@2.41-5
no fix listed
3
mcp/grafana:latest9362bcf6aa0e
util-linux@2.38.1-5+deb12u3
no fix listed
3
meshery/meshery:stable-latest44b64ee128fb
util-linux@2.38.1-5+deb12u3
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
util-linux@2.27.1-6ubuntu3.6
no fix listed
3
opencsghq/postgres:15.19b98600564e07
util-linux@2.41.5-0+deb13u1
no fix listed
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
util-linux@2.37.2-4ubuntu3
no fix listed
3
openebs/node-disk-operator:2.1.06afe2123c457
util-linux@2.37.2-4ubuntu3
no fix listed
3
selenium/hub:3.141.5902f251d48d5f
util-linux@2.34-0.1ubuntu9.1
no fix listed
3
sigp/lighthouse:latest-amd6450f66cfebb6d
util-linux@2.37.2-4ubuntu3.4
no fix listed
3
vaultwarden/server:1.37.1ebdfe70701c6
util-linux@2.41-5
no fix listed
3
xenondb/percona:5.7.330e26872a2b67
util-linux@2.34-0.1ubuntu9.1
no fix listed
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
util-linux@2.38.1-5+deb12u3
no fix listed
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
util-linux@2.38.1-5+deb12u2
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
util-linux@2.38.1-5+b1
no fix listed
3
ghcr.io/dgtlmoon/changedetection.io:0.60.7:latest096dae27b5d6
util-linux@2.38.1-5+deb12u3
no fix listed
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
util-linux@2.38.1-5+deb12u3
no fix listed
3
ghcr.io/flaresolverr/flaresolverr:latest:v3.5.2c80ae007ce2c
util-linux@2.38.1-5+deb12u3
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
util-linux@2.38.1-5+deb12u1
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
util-linux@2.38.1-5+deb12u3
no fix listed
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
util-linux@2.39.3-9ubuntu6.6
no fix listed
3
quay.io/cilium/cilium:v1.20.22939231d0d3e
util-linux@2.41.3-3ubuntu2.2
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
util-linux@2.38.1-5+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
util-linux@2.37.2-4ubuntu3
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
util-linux@2.39.3-9ubuntu6.2
no fix listed
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
util-linux@2.39.3-9ubuntu6.2
no fix listed
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
util-linux@2.39.3-9ubuntu6.2
no fix listed
3
quay.io/devtron/dashboard:0d8f6cf4-60e17132-931-39393aa61fffb8ae8
util-linux@2.42.1-r0
2.42.3-r0
3
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
util-linux@2.42.1-r0
2.42.3-r0
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
util-linux@2.39.3-9ubuntu6.2
no fix listed
3

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.