StackRadar

CVE-2026-76642

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,798
of 17,821 indexed, latest versions
Container images
2,815
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-76642 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,798 of 17,821 indexed charts deploy, on 2,815 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,547
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r0, 2.42.3-r0267
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-76642DEBIAN-CVE-2026-76642UBUNTU-CVE-2026-76642AZL-99081ECHO-b20e-705a-6d36

Charts affected

2,798 by stars
ChartLatestAffected imagesRadar Score
netbirdnetbird1.9.01 of 4See more

netbird netbird 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
util-linux@2.39.3-9ubuntu6.2
no fix listed

Open the chart page →

6,482
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
util-linux@2.39.3-9ubuntu6.4
no fix listed

Open the chart page →

1,598
neuralbank-stackneuralbank-stack0.1.01 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:latest4210a3296e7c
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,436
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
util-linux@2.39.3-9ubuntu6.2
no fix listed

Open the chart page →

7,652
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
util-linux@2.41-5
no fix listed

Open the chart page →

3,926
agent-control-bootstrapnewrelic1.8.161 of 1See more

agent-control-bootstrap newrelic 1.8.16

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:1.24.047520b65d6b2
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,000
nginx-appnginx-app0.1.21 of 1See more

nginx-app nginx-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,887
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,417
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,417
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

3,020
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

23,270
booksonicnicholaswildeVerified publisher1.0.11 of 1See more

booksonic nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

17,058
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

24,397
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

25,575
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

22,448
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

23,651
ciliumnicklasfrahm-ciliumVerified publisher0.7.42 of 6See more

cilium nicklasfrahm-cilium 0.7.4

2 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
util-linux@2.39.3-9ubuntu6.3
no fix listed
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

7,266
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/redis:8.2.24521b581dbdd
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,520
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

3,979
basenn-coVerified publisher0.1.01 of 1See more

base nn-co 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,593
base-jobnn-coVerified publisher0.1.01 of 4See more

base-job nn-co 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/ubuntu:latestda6fc2be5478
util-linux@2.41.3-3ubuntu2.2
no fix listed

Open the chart page →

338
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

10,456
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,993
firehose-corenodeifyVerified publisher1.2.62 of 2See more

firehose-core nodeify 1.2.6

2 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
util-linux@2.37.2-4ubuntu3.4
no fix listed
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

6,628
firehose-ethereumnodeifyVerified publisher1.7.12 of 2See more

firehose-ethereum nodeify 1.7.1

2 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
util-linux@2.37.2-4ubuntu3.4
no fix listed
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
util-linux@2.39.3-9ubuntu6.4
no fix listed

Open the chart page →

5,742
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

4,785
app1node-web-app10.1.31 of 1See more

app1 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,887
app2node-web-app10.1.31 of 1See more

app2 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,887
nginx-chartnomadshk-nginx0.1.01 of 1See more

nginx-chart nomadshk-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,887
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

22,831
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,872
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,618
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

6,839
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

15,370
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

15,443
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

15,426
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,899
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,855
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
util-linux@2.20.1-5.1ubuntu20.2
no fix listed

Open the chart page →

41,495
notifynl-omcnotifynlOfficialVerified publisher0.4.351 of 1See more

notifynl-omc notifynl 0.4.35

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
worthnl/notifynl-omc:2.2.16f58fc28252d
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

401
fluentd-kubernetes-daemonsetnovum-rgi-charts0.1.01 of 1See more

fluentd-kubernetes-daemonset novum-rgi-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
util-linux@2.41-5
no fix listed

Open the chart page →

1,055
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
linuxserver/codimd:latestb801bbcf6386
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

27,585
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
util-linux@2.31.1-0.4ubuntu3.4
no fix listed

Open the chart page →

95,465
nai-corenutanix-helm-releasesVerified publisher2.8.01 of 14See more

nai-core nutanix-helm-releases 2.8.0

1 of the 14 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
nutanix/nai-jobs:v2.8.09c373718e1b1
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

772
nai-operatorsnutanix-helm-releasesVerified publisher2.8.01 of 5See more

nai-operators nutanix-helm-releases 2.8.0

1 of the 5 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
nutanix/nai-jobs:v2.8.09c373718e1b1
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

772
cloakbrowser-mcpobeoneVerified publisher0.3.11 of 1See more

cloakbrowser-mcp obeone 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,347
firecrawlobeoneVerified publisher3.0.83 of 5See more

firecrawl obeone 3.0.8

3 of the 5 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/firecrawl:2.11.371ea2d420cea57
util-linux@2.38.1-5+deb12u3
no fix listed
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
util-linux@2.41-5
no fix listed
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

9,807
libretranslateobeoneVerified publisher1.0.71 of 1See more

libretranslate obeone 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
libretranslate/libretranslate:v1.9.61de2d7056bb8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,978
mktxpobeoneVerified publisher1.1.101 of 2See more

mktxp obeone 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/akpw/mktxp:latest0d96fec357d9
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

34
ollamaobeoneVerified publisher0.3.11 of 2See more

ollama obeone 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
util-linux@2.41-5
no fix listed

Open the chart page →

1,112

Container images carrying it

2,815 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-platform:prod61ff9287923a
util-linux@2.42.1-r0
2.42.3-r0
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
util-linux@2.41.4-r0
2.41.6-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
util-linux@2.41.4-r0
2.41.6-r0
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
util-linux@2.41-5
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.