CVE-2026-78408
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.9
- base score, highest
- EPSS
- 0.001
- 2nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,798
- of 17,821 indexed, latest versions
- Container images
- 2,815
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
CVE-2026-78408 affecting package util-linux 2.40.2-5
Carried by container images the latest versions of 2,798 of 17,821 indexed charts deploy, on 2,815 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| util-linuxdeb | 1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more | 2.41.5-0+deb13u1+e2 | 2,547 |
| util-linuxapk | 2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more | 2.41.6-r1, 2.42.3-r1 | 267 |
| util-linuxrpm | 2.40.2-4.azl3 | no fix listed | 1 |
Charts affected
2,798 by stars
Container images carrying it
2,815 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| chocobozzz/ | 052712130691 | util-linux | no fix listed | 1 |
| chriseaton/ | 54c3384ce701 | util-linux | no fix listed | 1 |
| chromadb/ | fc8dc8e11fb2 | util-linux | no fix listed | 1 |
| circleci/ | 9bdc62f02162 | util-linux | no fix listed | 1 |
| ciscolabs/ | 36d02faad958 | util-linux | no fix listed | 1 |
| citizenstig/ | b81c818ccb86 | util-linux | no fix listed | 1 |
| ckan/ | 87ecf3f27ad6 | util-linux | no fix listed | 1 |
| ckan/ | ef8e5d3e6be1 | util-linux | no fix listed | 1 |
| ckulka/ | 434bdd162247 | util-linux | no fix listed | 1 |
| clickhouse/ | 1ffa82edee00 | util-linux | no fix listed | 1 |
| clickhouse/ | 2e6587b81a26 | util-linux | no fix listed | 1 |
| clickhouse/ | 4f94badaca11 | util-linux | no fix listed | 1 |
| clickhouse/ | 512bb8a21483 | util-linux | no fix listed | 1 |
| clickhouse/ | 810861a2e2d0 | util-linux | no fix listed | 1 |
| clickhouse/ | 84d05b9c205e | util-linux | no fix listed | 1 |
| clickhouse/ | 8745843b17f9 | util-linux | no fix listed | 1 |
| clickhouse/ | 92098d3b31dd | util-linux | no fix listed | 1 |
| clickhouse/ | a65ca89ddbe8 | util-linux | no fix listed | 1 |
| clickhouse/ | a73b5c0fb6f8 | util-linux | no fix listed | 1 |
| clickhouse/ | b627d7a9bc0e | util-linux | no fix listed | 1 |
| clickhouse/ | d73903d1b61d | util-linux | no fix listed | 1 |
| clickhouse/ | dc5658853ce1 | util-linux | no fix listed | 1 |
| clickhouse/ | e019438e1e05 | util-linux | no fix listed | 1 |
| clickhouse/ | fa394da808cc | util-linux | no fix listed | 1 |
| cloudreve/ | f7a464100bf6 | util-linux | 2.41.6-r1 | 1 |
| cloudtooling/ | f4f04e0fc401 | util-linux | no fix listed | 1 |
| cloudtooling/ | db89d95f1d14 | util-linux | no fix listed | 1 |
| cloudve/ | af56e77ca587 | util-linux | no fix listed | 1 |
| cloudve/ | d79c1c5881c0 | util-linux | no fix listed | 1 |
| clowder/ | 11f3d844e4c0 | util-linux | no fix listed | 1 |
| clowder/ | fe97882672ca | util-linux | 2.41.6-r1 | 1 |
| clowder/ | 14155326c7b9 | util-linux | no fix listed | 1 |
| clowder/ | bf146f1ca24f | util-linux | no fix listed | 1 |
| cm2network/ | 8cba47f53df5 | util-linux | no fix listed | 1 |
| codedesignplus/ | 4fc116f5e879 | util-linux | no fix listed | 1 |
| codedesignplus/ | 7629e746a5b3 | util-linux | no fix listed | 1 |
| codedesignplus/ | 794a9b8cca1b | util-linux | no fix listed | 1 |
| codedesignplus/ | 95b620b601d9 | util-linux | no fix listed | 1 |
| collabora/ | 01dc4ab83977 | util-linux | no fix listed | 1 |
| collabora/ | 05299b452f7f | util-linux | no fix listed | 1 |
| conductoross/ | 9fba127693e6 | util-linux | no fix listed | 1 |
| consensys/ | 3a4f5761ae1c | util-linux | no fix listed | 1 |
| consensys/ | bf6ecd2ea716 | util-linux | no fix listed | 1 |
| consensys/ | f146a51a1ba3 | util-linux | no fix listed | 1 |
| contentsquareplatform/ | 24555f22d4be | util-linux | no fix listed | 1 |
| continuoussecuritytooling/ | f04ecefab64e | util-linux | no fix listed | 1 |
| copyparty/ | 0a0a8605062c | util-linux | 2.41.6-r1 | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | util-linux | no fix listed | 1 |
| cortezaproject/ | 8eb7a26605c9 | util-linux | no fix listed | 1 |
| cortezaproject/ | cb9f200de5d2 | util-linux | no fix listed | 1 |