You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
Nix,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
arc-consensus
d549d84d9fb8bdd8ea5c9c7397e…
One-liner (summary)
Description
| Status | Completed |
|---|---|
| Checksum (MD5) | a94c35b75b83612801aeca833188da08 |
| Checksum (SHA-1) | 8b4fef164679ffd21860aafcab264ba6300b4f36 |
| Checksum (SHA-256) | d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660 |
| Checksum (SHA-512) | 7167ea25faf7fdef9da9829a6643e8463b89f0e9cd7bd544af830324b5068452e9… |
| GPG Signature | |
| GPG Fingerprint | 2006bcbaea44c3d0630ff4e132ef04c02d67714a |
| Storage Region | Ohio, United States |
| Type | Binary (contains binaries and binary artifacts) |
| Uploaded At | 4 months, 4 weeks ago |
| Uploaded By |
|
| Slug Id | arc-consensus-h4aj |
| Unique Id | NleYUHcTzTGF |
| Version (Raw) | d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660 |
| Version (Parsed) |
|
| docker-specific metadata | |
| Image Digest | sha256:d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660 |
| Config Digest | sha256:d2a25cdd6c83aa8438409ca380a7cd768f4771f619c8679d63a630ce929504c5 |
| V1 OCI Index Digest | sha256:5547f609a303129bdfa240db16b9effdaad28c3e0c9b2b32d5038b7d37836630 |
| V1 Distribution (Signed) Digest | sha256:09206f7f2e533b429678f3a07f3f779d844fbac84adc7f2519a64f5a1bfd812b |
| V2 Distribution List Digest | sha256:381e805084cc2869fe97f4c3aedcd9c3b339026856af818d340e17d45ee0ed4e |
| V2 Distribution Digest | sha256:dfbc33d24cca4f13da5b48752fdbe15c47b61cbd54a887e6b8e40898d655ef60 |
| V1 Distribution Digest | sha256:35228c62ae6cc727b02026389debfc3ab48d8c27f4339c237f3658bfdac5b6e2 |
| V1 OCI Digest | sha256:d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660 |
| extended metadata | |
| Manifest Type | V1 OCI |
| Architecture | arm64 |
| Config | |
| Created | 2026-04-08 19:51:50 UTC |
| Os | linux |
This package was uploaded with the following V1 OCI manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.oci.image.manifest.v1+json",
"config": {
"mediaType": "application/vnd.oci.image.config.v1+json",
"digest": "sha256:a122277debdb5f3dee393c5a5d169183940358db416859828c9ea33c6abb9303",
"size": 4983
},
"layers": [
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:296b5494f17a830dcf9b0da028437305ab7ba3eaca4adf0dec9a463a18950079",
"size": 83844
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e",
"size": 12481
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:ef49c20a7b35aa995683f311510d35d77e203a2204f84de14a71a6d726e6af73",
"size": 440802
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4",
"size": 29005
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a",
"size": 67
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212",
"size": 188
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4",
"size": 123
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296",
"size": 162
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112",
"size": 80
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a",
"size": 351
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354",
"size": 314
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b",
"size": 131915
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:8f9d56b2cdc6271d2081cd7d118a289f1629dafbb95094c1c425e7d3c02a8257",
"size": 4962146
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:7c3092288799dc6783fefd722b313f9965b13945f05280a2a4e323a455db6dc4",
"size": 2339082
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:21cbe3884cdbb0396c8db4e6b3d1824ed28a3fd2f1ff68b902a1e4dc25aea592",
"size": 129166
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:ad3ef71fadeabd1cb426938d8788a109443599c17f473ac91e71b4b8f7fcd0a5",
"size": 741416
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:9cc52d140132c780b41914674bed78e473976a6bb9adae69364b67f6f3393c0a",
"size": 42721
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:0a304126184669a27af22f62c89725b6eefdb61cd7de6148e58160edb6c59fd2",
"size": 40326
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:6f7501424f1d1d86f808f38e50c28a353f1931f7074ae78cd6e1e698050c2ac0",
"size": 124295
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:cde4b2937ec7ee387b3a967f9eecbf615759c5f54f8060d0052a15351259d51f",
"size": 163
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:70372c2220f38c6ac5f235766681aca7d99d4ccdb8e0f8ec0f9e00d5f90d4716",
"size": 148
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:55c3283374ba3606723ee7fe72ae45975a041e317e29be79a437a6c8dd8f9771",
"size": 14033446
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:6c4a86ed1699a07984f543cdbbae40a7160095bf8e531ec880abef47d64cb106",
"size": 4758123
}
]
}
|
Digest:
sha256:296b5494f17a830dcf9b0da028437305ab7ba3eaca4adf0dec9a463a18950079
Command: bazel build @bookworm//base-files/arm64:data_statusd |
81.9 KB | ||
|
Digest:
sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e
Command: bazel build @bookworm//netbase/arm64:data_statusd |
12.2 KB | ||
|
Digest:
sha256:ef49c20a7b35aa995683f311510d35d77e203a2204f84de14a71a6d726e6af73
Command: bazel build @bookworm//tzdata/arm64:data_statusd |
430.5 KB | ||
|
Digest:
sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4
Command: bazel build @bookworm//media-types/arm64:data_statusd |
28.3 KB | ||
|
Digest:
sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a
Command: bazel build //common:rootfs |
67 bytes | ||
|
Digest:
sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212
Command: bazel build //common:passwd |
188 bytes | ||
|
Digest:
sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4
Command: bazel build //common:home |
123 bytes | ||
|
Digest:
sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296
Command: bazel build //common:group |
162 bytes | ||
|
Digest:
sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112
Command: bazel build //common:tmp |
80 bytes | ||
|
Digest:
sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a
Command: bazel build //static:nsswitch |
351 bytes | ||
|
Digest:
sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354
Command: bazel build //common:os_release_debian12 |
314 bytes | ||
|
Digest:
sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b
Command: bazel build //common:cacerts_debian12_arm64 |
128.8 KB | ||
|
Digest:
sha256:8f9d56b2cdc6271d2081cd7d118a289f1629dafbb95094c1c425e7d3c02a8257
Command: bazel build @bookworm//libc6/arm64:data_statusd |
4.7 MB | ||
|
Digest:
sha256:7c3092288799dc6783fefd722b313f9965b13945f05280a2a4e323a455db6dc4
Command: bazel build @bookworm//libssl3/arm64:data_statusd |
2.2 MB | ||
|
Digest:
sha256:21cbe3884cdbb0396c8db4e6b3d1824ed28a3fd2f1ff68b902a1e4dc25aea592
Command: bazel build @bookworm//libgomp1/arm64:data_statusd |
126.1 KB | ||
|
Digest:
sha256:ad3ef71fadeabd1cb426938d8788a109443599c17f473ac91e71b4b8f7fcd0a5
Command: bazel build @bookworm//libstdc++6/arm64:data_statusd |
724.0 KB | ||
|
Digest:
sha256:9cc52d140132c780b41914674bed78e473976a6bb9adae69364b67f6f3393c0a
Command: bazel build @bookworm//libgcc-s1/arm64:data_statusd |
41.7 KB | ||
|
Digest:
sha256:0a304126184669a27af22f62c89725b6eefdb61cd7de6148e58160edb6c59fd2
Command: bazel build @bookworm//gcc-12-base/arm64:data_statusd |
39.4 KB | ||
|
Digest:
sha256:6f7501424f1d1d86f808f38e50c28a353f1931f7074ae78cd6e1e698050c2ac0
Command: COPY /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt # buildkit |
121.4 KB | ||
|
Digest:
sha256:cde4b2937ec7ee387b3a967f9eecbf615759c5f54f8060d0052a15351259d51f
Command: COPY /tmp/passwd /etc/passwd # buildkit |
163 bytes | ||
|
Digest:
sha256:70372c2220f38c6ac5f235766681aca7d99d4ccdb8e0f8ec0f9e00d5f90d4716
Command: COPY /tmp/group /etc/group # buildkit |
148 bytes | ||
|
Digest:
sha256:55c3283374ba3606723ee7fe72ae45975a041e317e29be79a437a6c8dd8f9771
Command: COPY /tmp/arc-node-consensus /usr/local/bin/arc-node-consensus # buildkit |
13.4 MB | ||
|
Digest:
sha256:6c4a86ed1699a07984f543cdbbae40a7160095bf8e531ec880abef47d64cb106
Command: COPY /tmp/arc-snapshots /usr/local/bin/arc-snapshots # buildkit |
4.5 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE [27000/tcp 29000/tcp] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER arc |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/arc-node-consensus"] |
32 bytes |
|
|
arc-consensus |
11 |
|
||
|
|
arc-consensus |
17 |
|
||
|
|
arc-consensus |
22 |
|
||
|
|
arc-consensus |
86 |
|
||
|
|
arc-consensus |
92 |
|
||
|
|
arc-consensus |
10 |
|
||
|
|
arc-consensus |
3 |
|
||
|
|
arc-consensus |
1769 |
|
||
|
|
arc-consensus |
33 |
|
||
|
|
arc-consensus |
75 |
|
||
|
|
arc-consensus |
5 |
|
||
|
|
arc-consensus |
7 |
|
||
|
|
arc-consensus |
0 |
|
||
|
|
arc-consensus |
90 |
|
||
|
|
arc-consensus |
2 |
|
||
|
|
arc-consensus |
1 |
|
||
|
|
arc-consensus |
2 |
|
||
|
|
arc-consensus |
2 |
|
Last scanned
4 months, 4 weeks ago
Scan result
Vulnerable
Vulnerability count
21
Max. severity
High| Target: | NleYUHcTzTGF.sbom-cyclonedx.json (debian 12.13) | |
| HIGH |
CVE-2026-0861: glibc: Integer overflow in memalign leads to heap corruptionPassing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument. This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice. An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2025-15281: glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memoryCalling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org ubuntu.com www.cve.org www.openwall.com |
|
| MEDIUM |
CVE-2026-0915: glibc: glibc: Information disclosure via zero-valued network queryCalling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org ubuntu.com www.cve.org www.openwall.com |
|
| MEDIUM |
CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character setsThe iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: access.redhat.com nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server responseCalling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functionsCalling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-31790: openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public KeyIssue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: 3.0.19-1~deb12u2 References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org www.cve.org www.openwall.com |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: gcc-12-base Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2010-4756: glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressionsThe glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: cxib.net securityreason.com securityreason.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com nvd.nist.gov security.netapp.com www.cve.org |
|
| LOW |
CVE-2018-20796: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.cIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: www.securityfocus.com access.redhat.com debbugs.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.f5.com www.cve.org |
|
| LOW |
CVE-2019-1010022: glibc: stack guard protection bypassGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010023: glibc: running ldd on malicious ELF leads to code execution because of wrong size computationGNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010024: glibc: ASLR bypass using cache of thread stack and heapGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010025: glibc: information disclosure of heap addresses of pthread_created threadGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.Package Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-9192: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.cIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted patternPackage Name: libc6 Installed Version: 2.36-9+deb12u13 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org support.f5.com www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgcc-s1 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgomp1 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2025-27587: OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable ...OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: References: github.com minerva.crocs.fi.muni.cz |
|
| LOW |
CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TL ...Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: 3.0.19-1~deb12u2 References: github.com github.com github.com github.com github.com openssl-library.org www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28388: Issue summary: When a delta CRL that contains a Delta CRL Indicator ex ...Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: 3.0.19-1~deb12u2 References: github.com github.com github.com github.com github.com openssl-library.org www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28389: Issue summary: During processing of a crafted CMS EnvelopedData messag ...Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: 3.0.19-1~deb12u2 References: github.com github.com github.com github.com github.com openssl-library.org www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-28390: Issue summary: During processing of a crafted CMS EnvelopedData messag ...Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: 3.0.19-1~deb12u2 References: github.com github.com github.com github.com github.com openssl-library.org www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-31789: Issue summary: Converting an excessively large OCTET STRING value to a ...Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: libssl3 Installed Version: 3.0.18-1~deb12u2 Fixed Version: 3.0.19-1~deb12u2 References: github.com github.com github.com github.com github.com openssl-library.org www.cve.org www.openwall.com |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libstdc++6 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
These instructions assume you have setup the repository first (or read it).
To pull arc-consensus @ reference/tag sha256:d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660:
docker pull docker.cloudsmith.io/circle/arc-network/arc-consensus@sha256:d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660
You can also pull the latest version of this image (if it exists):
docker pull docker.cloudsmith.io/circle/arc-network/arc-consensus:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.cloudsmith.io/circle/arc-network/arc-consensus@sha256:d549d84d9fb8bdd8ea5c9c7397eb5175935fb9fc98e7aa8d9005f07b9a92b660