StackRadar

CVE-2026-78408

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,706
of 17,813 indexed, latest versions
Container images
2,697
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-78408 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,706 of 17,813 indexed charts deploy, on 2,697 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,433
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r1, 2.42.3-r1263
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-78408DEBIAN-CVE-2026-78408UBUNTU-CVE-2026-78408AZL-99393ECHO-3f6d-9602-8caa

Charts affected

2,706 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,697 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
util-linux@2.39.3-9ubuntu6
no fix listed
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
util-linux@2.39.3-9ubuntu6
no fix listed
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
util-linux@2.41-5
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
util-linux@2.39.3-9ubuntu6.1
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
util-linux@2.39.3-9ubuntu6.5
no fix listed
1
ghcr.io/mkutlak/alluredeck-ui:0.41.0c19509b1b336
util-linux@2.41.4-r0
2.41.6-r1
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
util-linux@2.41.5-0+deb13u1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
util-linux@2.38.1-5+b1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
util-linux@2.41-5
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
util-linux@2.37.2-4ubuntu3.4
no fix listed
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
util-linux@2.41.5-0+deb13u1
no fix listed
1
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
util-linux@2.39.3-9ubuntu6.5
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
util-linux@2.41.5-0+deb13u1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
util-linux@2.41-5
no fix listed
1
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
util-linux@2.41.4-r0
2.41.6-r1
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
util-linux@2.41-5
no fix listed
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
util-linux@2.39.3-9ubuntu6
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
util-linux@2.38.1-5+deb12u1
no fix listed
1
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
util-linux@2.41.3-3ubuntu2.2
no fix listed
1
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
util-linux@2.41-5
no fix listed
1
ghcr.io/nmshd/backbone-admin-cli:7.2.1f7d095c04a75
util-linux@2.39.3-9ubuntu6.5
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
util-linux@2.38.1-5+deb12u2
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
util-linux@2.41-5
no fix listed
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
util-linux@2.41-5
no fix listed
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
util-linux@2.41.5-0+deb13u1
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
util-linux@2.41-5
no fix listed
1
ghcr.io/observal/observal-web:1.13.1738acf65cba7
util-linux@2.42.1-r0
2.42.3-r1
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-1714527ca5d2a9
util-linux@2.41.4-r0
2.41.6-r1
1
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
util-linux@2.41.4-r0
2.41.6-r1
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
util-linux@2.41-5
no fix listed
1
ghcr.io/okteto/redis:0.0.0-2026-08-03:0.0.0-2026-08-1761a0169cf291
util-linux@2.41-r9
2.41.6-r1
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
util-linux@2.41-5
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
util-linux@2.38.1-5+deb12u1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
util-linux@2.41-r9
2.41.6-r1
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
util-linux@2.38.1-5+deb12u3
no fix listed
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.