StackRadar

CVE-2026-76642

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,738
of 17,828 indexed, latest versions
Container images
2,748
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-76642 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,738 of 17,828 indexed charts deploy, on 2,748 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,488
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r0, 2.42.3-r0259
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-76642DEBIAN-CVE-2026-76642UBUNTU-CVE-2026-76642AZL-99081ECHO-b20e-705a-6d36

Charts affected

2,738 by stars
ChartLatestAffected imagesRadar Score
convertigoconvertigoOfficialVerified publisher8.4.33 of 5See more

convertigo convertigo 8.4.3

3 of the 5 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
util-linux@2.38.1-5+deb12u2
no fix listed
library/convertigo:8.4.3faa719b117b2
util-linux@2.39.3-9ubuntu6.6
no fix listed
library/couchdb:3.4.22817ad50b5c5
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

17,018
cosmocosmo-platformOfficialVerified publisher0.20.05 of 10See more

cosmo cosmo-platform 0.20.0

5 of the 10 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
util-linux@2.38.1-5+deb12u1
no fix listed
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
util-linux@2.38.1-5+deb12u1
no fix listed
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
util-linux@2.38.1-5+deb12u3
no fix listed
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

29,756
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,437
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
util-linux@2.41-5
no fix listed

Open the chart page →

9,571
deepflowdeepflow6.2.2011 of 8See more

deepflow deepflow 6.2.201

1 of the 8 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

16,009
defectdojodefectdojo1.9.531See more

defectdojo defectdojo 1.9.53

1 container image this version deploys carries CVE-2026-76642.

Container imageDigestPackageFixed in
valkey/valkey:9.1.0-alpine3.23c9b77919daeb
util-linux@2.41.4-r0
2.41.6-r0

Open the chart page →

distrdistrOfficialVerified publisher4.0.31 of 4See more

distr distr 4.0.3

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

410
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
util-linux@2.39.3-9ubuntu6.1
no fix listed

Open the chart page →

4,239
dyff-apidyff-apiVerified publisher0.57.51 of 1See more

dyff-api dyff-api 0.57.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,370
edgelessdbedgelesssysVerified publisher0.3.21 of 1See more

edgelessdb edgelesssys 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

4,893
eratoerato0.6.21 of 3See more

erato erato 0.6.2

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/redis:8.8.0-alpine3.2309160599abd2
util-linux@2.41.4-r0
2.41.6-r0

Open the chart page →

371
zabbix-agentfermosit0.0.51 of 1See more

zabbix-agent fermosit 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
util-linux@2.39.3-9ubuntu6.1
no fix listed

Open the chart page →

2,435
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
util-linux@2.34-0.1ubuntu9.4
no fix listed

Open the chart page →

5,325
flyte-binaryflyte2.0.491 of 4See more

flyte-binary flyte 2.0.49

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,021
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
diygod/rsshub:latest22845ada2f14
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,434
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

10,693
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

9,851
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

10,296
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

10,867
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

11,978
gitvotegitvoteVerified publisher1.5.01 of 6See more

gitvote gitvote 1.5.0

1 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
util-linux@2.41-5
no fix listed

Open the chart page →

5,614
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

1,923
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,191
netbirdhelmforgeVerified publisher1.0.102 of 4See more

netbird helmforge 1.0.10

2 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed
netbirdio/netbird-server:0.78.13086534361a1
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

3,029
redishelmforgeVerified publisher3.0.01 of 1See more

redis helmforge 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

929
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.22 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
robustadev/krr:v1.30.0b8d782e568c7
util-linux@1:4.16.0-2+really2.41-5
no fix listed
ghcr.io/devops-ia/simple-krr-dashboard:1.6.34c625eff5410
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

2,197
typesensehmphuVerified publisher0.1.61 of 1See more

typesense hmphu 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
typesense/typesense:0.23.03accb727cbe2
util-linux@2.27.1-6ubuntu3.10
no fix listed

Open the chart page →

3,896
home-assistanthome-assistantVerified publisher0.5.102 of 3See more

home-assistant home-assistant 0.5.10

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.14.1fef0de769dcd
util-linux@2.42.1-r0
2.42.3-r0
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

2,361
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.24 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

4 of the 5 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
util-linux@2.38.1-5+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
util-linux@2.38.1-5+deb12u3
no fix listed
library/neo4j:2026.05.0-enterprise2caf944aa4a5
util-linux@2.41-5
no fix listed

Open the chart page →

10,521
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
util-linux@2.41-5
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
util-linux@2.41-5
no fix listed
instill/model-backend:611f0f2e980125e5ba5
util-linux@2.41-5
no fix listed

Open the chart page →

30,858
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
util-linux@2.39.3-9ubuntu6.1
no fix listed

Open the chart page →

4,553
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

4,593
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
util-linux@2.41.2-r0
2.41.6-r0

Open the chart page →

4,696
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

7,554
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/httpd:2.4454942557d44
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,251
klancesklances0.1.41 of 1See more

klances klances 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
util-linux@2.41-5
no fix listed

Open the chart page →

1,685
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/redis:6e7b96daa9a18
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,314
radondb-mysqlkubesphere-testVerified publisher1.0.11 of 3See more

radondb-mysql kubesphere-test 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

7,407
kubevpnkubevpn-charts2.11.91 of 1See more

kubevpn kubevpn-charts 2.11.9

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/kubenetworks/kubevpn:v2.11.93feb9da85270
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,690
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

59,093
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

33,982
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

15,534
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

7,967
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/mariadb:10.117f22313fc130
util-linux@2.37.2-4ubuntu3.6
no fix listed

Open the chart page →

2,345
memgraph-high-availabilitymemgraphVerified publisher1.4.11 of 2See more

memgraph-high-availability memgraph 1.4.1

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

1,258
kubecostmesosphere-stable0.37.52 of 9See more

kubecost mesosphere-stable 0.37.5

2 of the 9 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
util-linux@2.38.1-5+deb12u1
no fix listed
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

17,839
mogenius-operatormogeniusOfficialVerified publisher2.30.01 of 2See more

mogenius-operator mogenius 2.30.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

961
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,179
mariadbnicholaswildeVerified publisher1.0.61 of 1See more

mariadb nicholaswilde 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mariadb:version-110.4.21mariabionic7a94d7e89f52
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

9,675
observalobservalVerified publisher1.13.14 of 8See more

observal observal 1.13.1

4 of the 8 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3810861a2e2d0
util-linux@2.37.2-4ubuntu3.5
no fix listed
library/postgres:16f1c3376c26f2
util-linux@2.41.5-0+deb13u1
no fix listed
ghcr.io/observal/observal-api:1.13.1153b8b893232
util-linux@2.41-5
no fix listed
ghcr.io/observal/observal-web:1.13.1738acf65cba7
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

6,146

Container images carrying it

2,748 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

No deployed image carries CVE-2026-76642.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.