StackRadar

CVE-2026-76642

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,798
of 17,821 indexed, latest versions
Container images
2,815
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-76642 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,798 of 17,821 indexed charts deploy, on 2,815 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,547
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r0, 2.42.3-r0267
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-76642DEBIAN-CVE-2026-76642UBUNTU-CVE-2026-76642AZL-99081ECHO-b20e-705a-6d36

Charts affected

2,798 by stars
ChartLatestAffected imagesRadar Score
valkeymesosphere-stable3.0.221 of 1See more

valkey mesosphere-stable 3.0.22

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,682
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

8,973
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

4,385
miot-harnessmicroboxlabs0.7.01 of 1See more

miot-harness microboxlabs 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
util-linux@2.41-5
no fix listed

Open the chart page →

1,213
postgresmicroboxlabs0.3.01 of 1See more

postgres microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:16.6557fea37a744
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,963
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,142
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

4,610
apimicroslacVerified publisher0.1.01 of 2See more

api microslac 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

3,394
argomicroslacVerified publisher0.1.01 of 4See more

argo microslac 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.10.783c86003b781
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

9,977
mw-kube-agent-v3middleware-labsVerified publisher1.8.51 of 2See more

mw-kube-agent-v3 middleware-labs 1.8.5

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

2,101
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

72,161
folding-at-homemidokura-communityVerified publisher0.0.31 of 1See more

folding-at-home midokura-community 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
linuxserver/foldingathome:7.6.219a997426d71e
util-linux@2.39.3-9ubuntu6
no fix listed

Open the chart page →

2,965
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

11,361
parent-chartmid-proje0.1.01 of 3See more

parent-chart mid-proje 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
youssef11gaber10/flask-service:latest9c727fcfde76
util-linux@2.41-5
no fix listed

Open the chart page →

1,833
teimilvus-helm1.6.01 of 1See more

tei milvus-helm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,351
mini-blogmini-blog-helm0.1.03 of 3See more

mini-blog mini-blog-helm 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
util-linux@2.38.1-5+deb12u3
no fix listed
beyzkaya/blog-frontend:v1.0.0bf412d75c510
util-linux@2.41-r9
2.41.6-r0
library/postgres:159b1d34adbce1
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

13,246
MINTmint8.0.25 of 15See more

MINT mint 8.0.2

5 of the 15 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed
library/postgres:13-alpinefb9065b6e3e2
util-linux@2.41-r9
2.41.6-r0
library/redis:latest298e5b3bc566
util-linux@2.41.5-0+deb13u1
no fix listed
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
util-linux@2.34-0.1ubuntu9.3
no fix listed
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

114,848
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
util-linux@2.41-5
no fix listed

Open the chart page →

10,713
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
util-linux@2.41-5
no fix listed

Open the chart page →

10,704
session-scalermiqm0.1.01 of 1See more

session-scaler miqm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
miqm/session-scaler:0.1.0c5c211717d9b
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

3,237
helmmirasys-chart0.1.03 of 4See more

helm mirasys-chart 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
util-linux@2.39.3-9ubuntu6.5
no fix listed
library/redis:latest298e5b3bc566
util-linux@2.41.5-0+deb13u1
no fix listed
sepehrmdn/mirasys-assignment:1.0.12567228e33c8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,390
mi-tiendami-tienda0.1.01 of 1See more

mi-tienda mi-tienda 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:alpine72ba65eb42c1
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

34
mitosmitosVerified publisher1.6.01 of 7See more

mitos mitos 1.6.0

1 of the 7 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/mitos-run/mitos-forkd:v1.6.0979b462ab7d6
util-linux@2.37.2-4ubuntu3.5
no fix listed

Open the chart page →

3,067
simplewebappmlohrVerified publisher1.1.01 of 1See more

simplewebapp mlohr 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,887
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

10,141
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

7,173
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

11,851
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

11,851
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

12,266
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

16,351
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

11,635
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

19,410
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

6,245
mollysocketmollysocketVerified publisher0.2.81 of 1See more

mollysocket mollysocket 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

2,993
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,555
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,732
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,452
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

5,246
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,113
camera-viewermoreillonVerified publisher0.2.12 of 4See more

camera-viewer moreillon 0.2.1

2 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
util-linux@2.37.2-4ubuntu3.4
no fix listed
moreillon/camera-viewer:lateste418cc694bd5
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

11,728
group-managermoreillonVerified publisher0.4.42 of 3See more

group-manager moreillon 0.4.4

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
util-linux@2.37.2-4ubuntu3.4
no fix listed
moreillon/group-manager-front:v3.3.1c9f85db3baa5
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

9,917
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

11,037
user-manager-mongodbmoreillonVerified publisher0.6.23 of 4See more

user-manager-mongodb moreillon 0.6.2

3 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
util-linux@2.37.2-4ubuntu3.4
no fix listed
moreillon/user-manager-front:v5.0.3b067dbbbb6af
util-linux@2.38.1-5+b1
no fix listed
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

26,115
user-manager-neo4jmoreillonVerified publisher0.9.74 of 6See more

user-manager-neo4j moreillon 0.9.7

4 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
util-linux@2.37.2-4ubuntu3.4
no fix listed
moreillon/group-manager-front:v3.3.1c9f85db3baa5
util-linux@2.38.1-5+deb12u1
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
util-linux@2.38.1-5+b1
no fix listed
moreillon/user-manager-front:v5.1.06597e6b98d21
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

30,791
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

6,949
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

101,385
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

15,983
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2708162b8c094
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

5,643
codimdmt1905027.2.21 of 3See more

codimd mt190502 7.2.2

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,618
commafeedmt1905028.2.02 of 3See more

commafeed mt190502 8.2.0

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
util-linux@2.41-5
no fix listed
library/postgres:184ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

3,741

Container images carrying it

2,815 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-platform:prod61ff9287923a
util-linux@2.42.1-r0
2.42.3-r0
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
util-linux@2.41.4-r0
2.41.6-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
util-linux@2.41.4-r0
2.41.6-r0
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
util-linux@2.41-5
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.