StackRadar

CVE-2026-76642

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,798
of 17,821 indexed, latest versions
Container images
2,815
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-76642 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,798 of 17,821 indexed charts deploy, on 2,815 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,547
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r0, 2.42.3-r0267
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-76642DEBIAN-CVE-2026-76642UBUNTU-CVE-2026-76642AZL-99081ECHO-b20e-705a-6d36

Charts affected

2,798 by stars
ChartLatestAffected imagesRadar Score
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
util-linux@2.39.3-9ubuntu6.4
no fix listed

Open the chart page →

2,116
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

898
ocellusaiocellusaiVerified publisher0.1.121 of 2See more

ocellusai ocellusai 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
util-linux@2.41-5
no fix listed

Open the chart page →

1,203
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
util-linux@2.41-5
no fix listed

Open the chart page →

17,198
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
util-linux@2.41.2-r0
2.41.6-r0

Open the chart page →

2,358
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
util-linux@2.41-5
no fix listed

Open the chart page →

2,643
octant-uioctant-ui0.0.1-testing1 of 1See more

octant-ui octant-ui 0.0.1-testing

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
util-linux@2.41.4-r0
2.41.6-r0

Open the chart page →

1,107
mockoidcoidcmockVerified publisher0.0.11 of 1See more

mockoidc oidcmock 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
marcoimme/oidcmock:latestb6035c0721a8
util-linux@2.41-5
no fix listed

Open the chart page →

2,291
web-chartoje-ktcloudlab0.1.01 of 1See more

web-chart oje-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,887
ojp-serverojp0.1.51 of 1See more

ojp-server ojp 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
rrobetti/ojp:0.1.0-beta1141bd88232b
util-linux@2.39.3-9ubuntu6.1
no fix listed

Open the chart page →

2,665
automx2oleds-helm-chartsVerified publisher1.0.51 of 1See more

automx2 oleds-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
oled01/automx2:2025.1.105d3e398e675
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,335
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,833
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

8,156
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

9,327
laravel-appoli-the-devVerified publisher2.0.171 of 1See more

laravel-app oli-the-dev 2.0.17

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

2,852
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim48e4b67d85f8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,151
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
util-linux@2.41-5
no fix listed

Open the chart page →

4,703
cron-jobonechart-slVerified publisher0.73.71 of 1See more

cron-job onechart-sl 0.73.7

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/debian:stable-slim5bc3287b2540
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

583
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
util-linux@2.39.3-9ubuntu6.2
no fix listed

Open the chart page →

6,191
ontoserverontoserverVerified publisher0.5.21 of 2See more

ontoserver ontoserver 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,272
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest473fdffe4e67
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

6,772
erigonop-chartsVerified publisher0.0.51 of 2See more

erigon op-charts 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

2,933
opds-shelfopds-shelfVerified publisher0.4.01 of 3See more

opds-shelf opds-shelf 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

4,415
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

9,738
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,771
jobopen-charts2.0.01 of 1See more

job open-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

761
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

3,927
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

3,741
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
util-linux@2.31.1-0.4ubuntu3.3
no fix listed
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

63,782
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
util-linux@2.27.1-6ubuntu3.6
no fix listed
omecproject/onos-progran:1.0.05715e5648aa0
util-linux@2.27.1-6ubuntu3.3
no fix listed
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

264,295
comac-cuopencord0.1.11 of 4See more

comac-cu opencord 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
util-linux@2.31.1-0.4ubuntu3.1
no fix listed

Open the chart page →

8,232
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

84,116
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
util-linux@2.31.1-0.4ubuntu3.5
no fix listed

Open the chart page →

15,761
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
util-linux@2.27.1-6ubuntu3.6
no fix listed
woojoong/wowza:latestec230db19652
util-linux@2.31.1-0.4ubuntu3.2
no fix listed

Open the chart page →

43,095
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

29,561
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
util-linux@2.27.1-6ubuntu3.6
no fix listed
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
util-linux@2.31.1-0.4ubuntu3.1
no fix listed

Open the chart page →

16,017
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

14,908
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
util-linux@2.27.1-6ubuntu3.10
no fix listed
omecproject/c3po-hssdb:master-latest28a90cc26716
util-linux@2.34-0.1ubuntu9.1
no fix listed
omecproject/mme-exporter:paging-latestbcc5f19fd676
util-linux@2.31.1-0.4ubuntu3.4
no fix listed
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
omecproject/openmme:master-latest64776cb9edb3
util-linux@2.27.1-6ubuntu3.10
no fix listed

Open the chart page →

108,608
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
util-linux@2.31.1-0.4ubuntu3.4
no fix listed

Open the chart page →

12,952
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
util-linux@2.27.1-6ubuntu3.3
no fix listed

Open the chart page →

98,804
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
util-linux@2.27.1-6ubuntu3.4
no fix listed

Open the chart page →

4,192
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
util-linux@2.27.1-6ubuntu3.7
no fix listed

Open the chart page →

69,510
sebaopencord1.0.06 of 17See more

seba opencord 1.0.0

6 of the 17 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
util-linux@2.27.1-6ubuntu3.3
no fix listed
voltha/voltha-cli:1.6.0c4e41e92f046
util-linux@2.27.1-6ubuntu3.6
no fix listed
voltha/voltha-envoy:1.6.059ab2a00f712
util-linux@2.20.1-5.1ubuntu20.9
no fix listed
voltha/voltha-netconf:1.6.037f80524c207
util-linux@2.27.1-6ubuntu3.6
no fix listed
voltha/voltha-ofagent:1.6.09ee8c1f4428c
util-linux@2.27.1-6ubuntu3.6
no fix listed
voltha/voltha-voltha:1.6.0ff596b62de59
util-linux@2.27.1-6ubuntu3.6
no fix listed

Open the chart page →

378,088
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
util-linux@2.31.1-0.4ubuntu3.5
no fix listed
library/ubuntu:16.041f1a2d56de1d
util-linux@2.27.1-6ubuntu3.10
no fix listed
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
voltha/voltha-onos:5.1.8e038acb950d3
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

41,198
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

11,224
opencost-lensopencost-lens1.0.01 of 2See more

opencost-lens opencost-lens 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

1,114
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
util-linux@2.37.2-4ubuntu3.5
no fix listed

Open the chart page →

1,757
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

5,230
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,420
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-76642.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

3,486

Container images carrying it

2,815 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-platform:prod61ff9287923a
util-linux@2.42.1-r0
2.42.3-r0
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
util-linux@2.41.4-r0
2.41.6-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
util-linux@2.41.4-r0
2.41.6-r0
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
util-linux@2.41-5
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.