CVE-2026-78408
HighAdvisory
Published 2 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.9
- base score, highest
- EPSS
- 0.001
- 2nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,723
- of 17,790 indexed, latest versions
- Container images
- 2,688
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
CVE-2026-78408 affecting package util-linux 2.40.2-5
Carried by container images the latest versions of 2,723 of 17,790 indexed charts deploy, on 2,688 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| util-linuxdeb | 1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:4.16.0-2+really2.41-5, 2.20.1-5.1ubuntu20.2+46 more | 2.41.5-0+deb13u1+e2 | 2,410 |
| util-linuxapk | 2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more | 2.41.6-r1, 2.42.3-r1 | 277 |
| util-linuxrpm | 2.40.2-4.azl3 | no fix listed | 1 |
- OSV records
- ALPINE-CVE-2026-78408DEBIAN-CVE-2026-78408UBUNTU-CVE-2026-78408AZL-99393ECHO-3f6d-9602-8caa
- Trending
- Rank 25 in indexed charts, since 5 Sept 2026. See the ranking →
Charts affected
2,723 by stars
Container images carrying it
2,688 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| guacamole/ | f344085e618b | util-linux | no fix listed | 3 |
| hetznercloud/ | 024ea4b07161 | util-linux | 2.42.3-r1 | 3 |
| jacobalberty/ | 896c0ab82d33 | util-linux | no fix listed | 3 |
| library/ | e05bc1169fb2 | util-linux | no fix listed | 3 |
| library/ | ab1c3dd38194 | util-linux | no fix listed | 3 |
| library/ | 81a1c8842a09 | util-linux | no fix listed | 3 |
| library/ | a484819eb602 | util-linux | no fix listed | 3 |
| library/ | be23f54a88d3 | util-linux | no fix listed | 3 |
| library/ | 727876d27466 | util-linux | 2.42.3-r1 | 3 |
| library/ | 78387bc3881b | util-linux | no fix listed | 3 |
| library/ | ffd1b50c522a | util-linux | no fix listed | 3 |
| library/ | 33ceb71981b6 | util-linux | no fix listed | 3 |
| louislam/ | 917318f9d7be | util-linux | no fix listed | 3 |
| mcp/ | 9362bcf6aa0e | util-linux | no fix listed | 3 |
| omecproject/ | d59ccb138ffb | util-linux | no fix listed | 3 |
| selenium/ | 02f251d48d5f | util-linux | no fix listed | 3 |
| sigp/ | 50f66cfebb6d | util-linux | no fix listed | 3 |
| vaultwarden/ | ebdfe70701c6 | util-linux | no fix listed | 3 |
| xenondb/ | 0e26872a2b67 | util-linux | no fix listed | 3 |
| ecr-public.aws.com/ | 2cc044fc5a07 | util-linux | 2.41.6-r1 | 3 |
| ghcr.io/ | 19ebe07b4daf | util-linux | no fix listed | 3 |
| ghcr.io/ | 6a5594b7b32c | util-linux | no fix listed | 3 |
| ghcr.io/ | cf9b41e17b93 | util-linux | no fix listed | 3 |
| ghcr.io/ | a1bc133af84e | util-linux | 2.42.3-r1 | 3 |
| ghcr.io/ | 0502794a4d86 | util-linux | no fix listed | 3 |
| ghcr.io/ | 673d5229df1f | util-linux | no fix listed | 3 |
| ghcr.io/ | a89736c586ba | util-linux | no fix listed | 3 |
| quay.io/ | dd3f47d5a5e4 | util-linux | no fix listed | 3 |
| quay.io/ | 6545dac92173 | util-linux | no fix listed | 3 |
| quay.io/ | 2b6db27eaf3d | util-linux | no fix listed | 3 |
| quay.io/ | 5bf041aacadd | util-linux | no fix listed | 3 |
| quay.io/ | 60566529446a | util-linux | no fix listed | 3 |
| quay.io/ | 721b5c9634d4 | util-linux | no fix listed | 3 |
| quay.io/ | aa61fffb8ae8 | util-linux | 2.42.3-r1 | 3 |
| quay.io/ | c63823af3835 | util-linux | 2.42.3-r1 | 3 |
| quay.io/ | 9795f3f9f031 | util-linux | no fix listed | 3 |
| quay.io/ | 39f2c6e0af38 | util-linux | no fix listed | 3 |
| quay.io/ | 01d5d8c4cecb | util-linux | no fix listed | 3 |
| quay.io/ | 4c3b91bebd3d | util-linux | no fix listed | 3 |
| quay.io/ | f296c2ec5db7 | util-linux | no fix listed | 3 |
| quay.io/ | 9d25865295af | util-linux | no fix listed | 3 |
| quay.io/ | ea6dd1e4ce71 | util-linux | no fix listed | 3 |
| quay.io/ | 709c7da19c5a | util-linux | no fix listed | 3 |
| actualbudget/ | 552beab3dec8 | util-linux | no fix listed | 2 |
| alazidis/ | 0e8c84152201 | util-linux | no fix listed | 2 |
| apache/ | 9ee5df1611f9 | util-linux | no fix listed | 2 |
| apache/ | 0116fb802786 | util-linux | no fix listed | 2 |
| apache/ | 7cdfd8deec92 | util-linux | no fix listed | 2 |
| apache/ | 319cd8a81ed1 | util-linux | no fix listed | 2 |
| apache/ | ae0b86d3c4d0 | util-linux | no fix listed | 2 |