StackRadar

CVE-2026-78408

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,798
of 17,821 indexed, latest versions
Container images
2,815
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-78408 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,798 of 17,821 indexed charts deploy, on 2,815 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,547
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r1, 2.42.3-r1267
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-78408DEBIAN-CVE-2026-78408UBUNTU-CVE-2026-78408AZL-99393ECHO-3f6d-9602-8caa

Charts affected

2,798 by stars
ChartLatestAffected imagesRadar Score
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

9,069
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
util-linux@2.41-5
no fix listed

Open the chart page →

13,745
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
util-linux@2.39.3-9ubuntu6.1
no fix listed

Open the chart page →

4,105
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
util-linux@2.41.5-0+deb13u1
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,416
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

1,931
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

3,982
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

3,982
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

15,342
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

12,819
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
util-linux@2.41-5
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
util-linux@2.41-5
no fix listed

Open the chart page →

9,103
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,459
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
util-linux@2.41-5
no fix listed

Open the chart page →

2,292
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
util-linux@2.39.3-9ubuntu6.4
no fix listed

Open the chart page →

4,105
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,213
vite-react-app-helm-chartsvite-react-app-helm-charts1.0.01 of 1See more

vite-react-app-helm-charts vite-react-app-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/vite-app-sample:latest21247f2b97c4
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

1,083
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

7,098
waldurwaldur-chartsVerified publisher8.1.23 of 3See more

waldur waldur-charts 8.1.2

3 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
util-linux@2.41.5-0+deb13u1
no fix listed
opennode/waldur-homeport:8.1.2a8b5b4777027
util-linux@2.42.1-r0
2.42.3-r1
opennode/waldur-mastermind:8.1.24c82b15d9042
util-linux@2.41-5
no fix listed

Open the chart page →

4,599
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

16,053
reflectorwener10.0.651 of 1See more

reflector wener 10.0.65

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

723
kube-prometheus-stackwenerme91.4.11 of 6See more

kube-prometheus-stack wenerme 91.4.1

1 of the 6 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

682
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
util-linux@2.20.1-5.1ubuntu20.2
no fix listed

Open the chart page →

41,495
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

56,318
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
util-linux@2.41-5
no fix listed

Open the chart page →

7,847
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
util-linux@2.41-5
no fix listed

Open the chart page →

8,524
workflows-aggregatorworkflows-aggregatorVerified publisher0.16.91 of 1See more

workflows-aggregator workflows-aggregator 0.16.9

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

1,419
workflows-sinkworkflows-sinkVerified publisher0.16.31 of 1See more

workflows-sink workflows-sink 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,447
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

9,302
discord-botxxczakiVerified publisher0.30.01 of 2See more

discord-bot xxczaki 0.30.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
xxczaki/discord-bot:43f7a4063e233a10bcd9bf3bcbbfe3f26d563513d09dccf45284
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

478
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

9,891
yugawareyugabyteVerified publisher2026.1.11 of 3See more

yugaware yugabyte 2026.1.1

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:14.22eba8ddbdd837
util-linux@2.41-5
no fix listed

Open the chart page →

2,620
qleverzazukoVerified publisher0.7.11 of 2See more

qlever zazuko 0.7.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-server:v0.10.11de7869ab46e
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

2,523
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
util-linux@2.41-5
no fix listed

Open the chart page →

2,874
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,388
mikochizer0tonin1.11.01 of 1See more

mikochi zer0tonin 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.11.009872bae1554
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

1,017
backendzymtraceOfficialVerified publisher26.9.24 of 6See more

backend zymtrace 26.9.2

4 of the 6 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
util-linux@2.37.2-4ubuntu3.4
no fix listed
library/postgres:17.4304ab8135187
util-linux@2.38.1-5+deb12u3
no fix listed
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
util-linux@2.37.2-4ubuntu3.4
no fix listed
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.29a32b89c0c19
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

9,248
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
util-linux@2.31.1-0.4ubuntu3.3
no fix listed

Open the chart page →

78,855
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

4,527
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

3,307
open5gsadaptivenetlabVerified publisher1.0.32 of 3See more

open5gs adaptivenetlab 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
free5gmano/nextepc-mongodb:latest36f806935519
util-linux@2.27.1-6ubuntu3.6
no fix listed
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

104,094
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

2,451
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

6,300
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,306
linkstackadnoctemVerified publisher0.4.01 of 1See more

linkstack adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
linkstackorg/linkstack:latest1c8b05399ee4
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

2,096
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,913
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
util-linux@2.41-5
no fix listed

Open the chart page →

1,285
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

30,728
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/aerokube/jumphost:1.0.170fd7c00418d
util-linux@2.37.2-4ubuntu3.3
no fix listed
quay.io/aerokube/keygen:1.0.1578934444f04
util-linux@2.37.2-4ubuntu3.3
no fix listed

Open the chart page →

7,964
msockperfaetrius2.0.82 of 2See more

msockperf aetrius 2.0.8

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
util-linux@2.39.3-9ubuntu6
no fix listed
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
util-linux@2.39.3-9ubuntu6
no fix listed

Open the chart page →

4,297
kourierahhhhVerified publisher0.18.11 of 1See more

kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.34-latestcfc0678bc03c
util-linux@2.37.2-4ubuntu3.5
no fix listed

Open the chart page →

1,832
ahnlich-dbahnlich-dbVerified publisher0.1.11 of 1See more

ahnlich-db ahnlich-db 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
util-linux@2.41-5
no fix listed

Open the chart page →

1,636

Container images carrying it

2,815 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-platform:prod61ff9287923a
util-linux@2.42.1-r0
2.42.3-r1
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
util-linux@2.41.4-r0
2.41.6-r1
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
util-linux@2.41.4-r0
2.41.6-r1
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
util-linux@2.41-5
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.