StackRadar

CVE-2026-78408

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,706
of 17,813 indexed, latest versions
Container images
2,697
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-78408 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,706 of 17,813 indexed charts deploy, on 2,697 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,433
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r1, 2.42.3-r1263
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-78408DEBIAN-CVE-2026-78408UBUNTU-CVE-2026-78408AZL-99393ECHO-3f6d-9602-8caa

Charts affected

2,706 by stars
ChartLatestAffected imagesRadar Score
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

9,642
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
util-linux@2.34-0.1ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

20,279
matrix-stackrock8sVerified publisher0.8.12 of 7See more

matrix-stack rock8s 0.8.1

2 of the 7 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
util-linux@2.42.1-r0
2.42.3-r1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

9,492
reviewboardrock8sVerified publisher0.0.12 of 3See more

reviewboard rock8s 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
util-linux@2.37.2-4ubuntu3.5
no fix listed
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

6,248
monitoringrocketchat-server0.0.172 of 9See more

monitoring rocketchat-server 0.0.17

2 of the 9 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
util-linux@2.41-r9
2.41.6-r1
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

7,049
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,792
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

9,771
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

13,204
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

4,712
devtron-enterpriseromholdings48.0.09 of 28See more

devtron-enterprise romholdings 48.0.0

9 of the 28 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/dashboard:0d8f6cf4-60e17132-931-39393aa61fffb8ae8
util-linux@2.42.1-r0
2.42.3-r1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
util-linux@2.38.1-5+b1
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
util-linux@2.27.1-6ubuntu3.10
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
util-linux@2.38.1-5+deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

69,641
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

4,993
devtron-operatorromholdings0.23.36 of 11See more

devtron-operator romholdings 0.23.3

6 of the 11 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
util-linux@2.42.1-r0
2.42.3-r1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
util-linux@2.38.1-5+b1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
util-linux@2.39.3-9ubuntu6.2
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

33,387
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

12,000
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,951
rommromm-helm-chartVerified publisher1.5.52 of 3See more

romm romm-helm-chart 1.5.5

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/mariadb:112439dcd7d140
util-linux@2.39.3-9ubuntu6.5
no fix listed
rommapp/romm:5.2.03512f2ca4557
util-linux@2.41.2-r0
2.41.6-r1

Open the chart page →

3,468
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
util-linux@2.34-0.1ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

20,279
endeavorrotationalVerified publisher1.3.12 of 2See more

endeavor rotational 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
rotationalio/endeavor:1.3.0ac566baddc06
util-linux@2.38.1-5+deb12u3
no fix listed
rotationalio/quarterdeck:0.16.00e7ad3a031dc
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,296
genoarotationalVerified publisher1.4.01 of 1See more

genoa rotational 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
rotationalio/genoa:1.2.03ab583519215
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,018
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,209
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,374
quarterdeckrotationalVerified publisher0.16.01 of 1See more

quarterdeck rotational 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
rotationalio/quarterdeck:0.16.00e7ad3a031dc
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,189
routehub-serverroutehub-helm1.0.12 of 3See more

routehub-server routehub-helm 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
util-linux@2.34-0.1ubuntu9.4
no fix listed
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

7,012
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,592
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,798
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

1,740
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
util-linux@2.37.2-4ubuntu3.5
no fix listed

Open the chart page →

7,818
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

5,362
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
util-linux@2.41-5
no fix listed

Open the chart page →

10,767
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

4,598
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

1,737
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

27,857
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
util-linux@2.41-5
no fix listed

Open the chart page →

2,661
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

7,505
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

34,712
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
util-linux@2.41-5
no fix listed

Open the chart page →

2,097
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
util-linux@2.41-5
no fix listed

Open the chart page →

2,577
smokepingrubxkubeVerified publisher1.2.11 of 1See more

smokeping rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.9.02f4488c9afcd
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

915
spindlerubxkubeVerified publisher0.1.21 of 2See more

spindle rubxkube 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

1,175
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

6,341
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

1,692
tranquil-pdsrubxkubeVerified publisher0.2.01 of 2See more

tranquil-pds rubxkube 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

635
trmnl-serverrubxkubeVerified publisher0.1.01 of 2See more

trmnl-server rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/python:3.14-slimcad9a2c87176
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

2,954
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

30,810
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
util-linux@2.41-5
no fix listed

Open the chart page →

1,788
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,468
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

3,837
rybbitrybbit-helm1.3.22See more

rybbit rybbit-helm 1.3.2

2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-alpine15568b9cb7eb
util-linux@2.42.1-r0
2.42.3-r1
valkey/valkey:9.1.164e361b630ec
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

nadekobotryuunosukeds30.1.22 of 2See more

nadekobot ryuunosukeds3 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
util-linux@2.41.3-3ubuntu2
no fix listed
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

8,821
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,702
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
util-linux@2.41-5
no fix listed

Open the chart page →

9,792

Container images carrying it

2,697 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

No deployed image carries CVE-2026-78408.

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.