StackRadar

CVE-2026-78408

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,798
of 17,828 indexed, latest versions
Container images
2,822
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-78408 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,798 of 17,828 indexed charts deploy, on 2,822 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,558
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r1, 2.42.3-r1263
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-78408DEBIAN-CVE-2026-78408UBUNTU-CVE-2026-78408AZL-99393ECHO-3f6d-9602-8caa

Charts affected

2,798 by stars
ChartLatestAffected imagesRadar Score
librenmslibrenms10.1.22 of 5See more

librenms librenms 10.1.2

2 of the 5 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/redis:8.10.1602d361c4da9
util-linux@2.41.5-0+deb13u1
no fix listed
librenms/librenms:26.8.28194a4a9ff49
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

2,743
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

4,501
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
util-linux@2.38.1-5+deb12u2
no fix listed
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

5,453
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

38,690
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.41 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

1 of the 5 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

2,999
weblinzhengen0.1.71 of 1See more

web linzhengen 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,965
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

2,712
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
util-linux@2.41-5
no fix listed

Open the chart page →

1,168
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

1,560
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
util-linux@2.41.2-r0
2.41.6-r1

Open the chart page →

1,006
liturgical-appliturgical0.9.01 of 1See more

liturgical-app liturgical 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

955
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

10,874
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
util-linux@2.34-0.1ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

20,350
web-chartljw-ktcloudlab0.1.01 of 1See more

web-chart ljw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,589
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
util-linux@2.41-5
no fix listed

Open the chart page →

13,114
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

2,486
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
util-linux@2.41-5
no fix listed

Open the chart page →

2,681
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
util-linux@2.41.2-r0
2.41.6-r1

Open the chart page →

1,395
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,986
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

949
volume-testlocal-pv0.1.01 of 1See more

volume-test local-pv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/nginx:stable-alpinedc5069ad14f1
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

34
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

7,583
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

33,939
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
util-linux@2.37.2-4ubuntu3.5
no fix listed

Open the chart page →

2,568
elasticvuelogic3579Verified publisher1.15.01 of 1See more

elasticvue logic3579 1.15.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
cars10/elasticvue:1.15.0efddf4fa0fd8
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

1,083
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
util-linux@2.39.3-9ubuntu6.5
no fix listed
flashcatcloud/nightingale:8.5.1421acb36181b
util-linux@2.41-5
no fix listed
library/redis:6.2e7b96daa9a18
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

9,147
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

6,727
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

6,619
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

23,820
logtidelogtideVerified publisher2.1.141 of 4See more

logtide logtide 2.1.14

1 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

2,823
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

5,953
allure_docker_servicelovemew67Verified publisher0.0.11 of 1See more

allure_docker_service lovemew67 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.27.00815040339a9
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

62,599
mongo_guilovemew67Verified publisher0.0.21 of 1See more

mongo_gui lovemew67 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.1.1e3952b14ae8e
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

2,015
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,908
vulnerability-scaninglovemew67Verified publisher0.0.31 of 2See more

vulnerability-scaning lovemew67 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.35.14154286c0209
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

5,280
loxilbloxilbVerified publisher0.1.02 of 2See more

loxilb loxilb 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
util-linux@2.37.2-4ubuntu3.5
no fix listed
ghcr.io/loxilb-io/loxilb:latesta475b43946b3
util-linux@2.37.2-4ubuntu3.6
no fix listed

Open the chart page →

4,467
lsdisklsdiskVerified publisher2.0.71 of 4See more

lsdisk lsdisk 2.0.7

1 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,088
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

89,174
redislsst-sqre1.2.11 of 1See more

redis lsst-sqre 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,008
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/redis:6.2143f7bfc2358
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,666
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
elastictranscoder/media-storage:f6d861a026208b8c2359
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
elastictranscoder/transcoder:627e21dcb4a0327029e6
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

58,521
flaresolverrluiscajl0.0.31 of 1See more

flaresolverr luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:latest139dfee1c6f8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

27,797
plex-rclone-wireguardluiscajl1.0.191 of 2See more

plex-rclone-wireguard luiscajl 1.0.19

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

907
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
util-linux@2.41.4-r0
2.41.6-r1

Open the chart page →

1,165
bazarrm0nsterrr-bazarrVerified publisher2.3.11 of 1See more

bazarr m0nsterrr-bazarr 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.6.1e5d192a6f62a
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

131
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
util-linux@2.41-5
no fix listed

Open the chart page →

4,725
jellyfinm0nsterrr-jellyfinVerified publisher2.3.51 of 1See more

jellyfin m0nsterrr-jellyfin 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
util-linux@2.41-5
no fix listed

Open the chart page →

2,681
kea-exporterm0nsterrr-kea-exporterVerified publisher2.2.11 of 1See more

kea-exporter m0nsterrr-kea-exporter 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
util-linux@2.41-5
no fix listed

Open the chart page →

1,097
qbittorrentm0nsterrr-qbittorrentVerified publisher7.1.21 of 2See more

qbittorrent m0nsterrr-qbittorrent 7.1.2

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.2.34fcf15b7f265
util-linux@2.42-r0
2.42.3-r1

Open the chart page →

764
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

9,850

Container images carrying it

2,822 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-platform:prod61ff9287923a
util-linux@2.42.1-r0
2.42.3-r1
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
util-linux@2.41.4-r0
2.41.6-r1
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
util-linux@2.41.4-r0
2.41.6-r1
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
util-linux@2.41-5
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.