Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, Nix, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public circle circle / arc-network
Public repository for ARC blockchain release images

Docker logo arc-consensus  e7e7ad8abb32655d220259e4921…

One-liner (summary)

A certifiably-awesome package curated by arc-publisher-gha-service, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by arc-publisher-gha-service, hosted by Cloudsmith.

License

Unknown

Size

26.7 MB

Downloads

17

Tags

image amd64 linux

Status  Completed
Checksum (MD5) 41e6cc2cf535ee886f3ecc9fb4adedd1
Checksum (SHA-1) 9904ceecd8ab3c897786c0961da3a42689de59ac
Checksum (SHA-256) e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e
Checksum (SHA-512) 7d83f887f3aec28e5000a52146b612df5e2bbe167e4f7a3fcef4f424a594af6f5e…
GPG Signature
GPG Fingerprint 2006bcbaea44c3d0630ff4e132ef04c02d67714a
Storage Region  Ohio, United States
Type  Binary (contains binaries and binary artifacts)
Uploaded At 1 month, 2 weeks ago
Uploaded By Uploaded by arc-publisher-gha-service
Slug Id arc-consensus-biub
Unique Id ko52Za0FtcBw
Version (Raw) e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e
Config Digest sha256:590518e6a7ab26b9591e45ec76b951018908d68e43a8055eaf0f89e09ab56df8
V1 OCI Index Digest sha256:e2e307fed1206290d7074bc37cd2ba0b8c24e8d9466268f08c2f7160f2dbf976
V1 Distribution (Signed) Digest sha256:999341d775d93bbc895f8e8fb054db13f7ffce86860e018d3ac73de07a8c5383
V2 Distribution List Digest sha256:600b57724501f210c6803bec07a26f1b55101d9d6b893a81efe43fc793f41c55
V2 Distribution Digest sha256:e3151139a6e2c4f02734c69a2c6e61f8ff99e025b15555c27e9c8b272d545f8b
V1 Distribution Digest sha256:c863c98ba71cc6b4e8cba58ec51a39178d8817f89a50c17763484625e82d5605
V1 OCI Digest sha256:e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e
  extended metadata
Manifest Type V1 OCI
Architecture amd64
Config
Created 2026-07-20 18:41:08 UTC
Os linux

This package was uploaded with the following V1 OCI manifest:

{
  "schemaVersion": 2,
  "mediaType": "application/vnd.oci.image.manifest.v1+json",
  "config": {
    "mediaType": "application/vnd.oci.image.config.v1+json",
    "digest": "sha256:ea6205110afacbcbcaf0fd0482c548ea66190b9463c38e49e08b7f57f4ef6986",
    "size": 4983
  },
  "layers": [
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:a5789fc40e828c4e7467626e3f69ec5dea8e5da22fe660db8ae6d16f777b0bbf",
      "size": 83900
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e",
      "size": 12481
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:39dc083afc39bd8dc43d456fe7ff7d39292e593bb2769972c11bb2e5f9119386",
      "size": 445709
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4",
      "size": 29005
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a",
      "size": 67
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212",
      "size": 188
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4",
      "size": 123
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296",
      "size": 162
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112",
      "size": 80
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a",
      "size": 351
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354",
      "size": 314
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b",
      "size": 131915
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:235c3625d753c5b8a741210c2e7fb26b47a0d02cf49acc631a38dcf847eedf89",
      "size": 4951123
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:dc0fb75e565a59a5824baedc9645656d17bc91c4b31332ee179580fa9f60eacd",
      "size": 2506537
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:336f6c853c4e7eaa77938f48c9b7ce98841916930fb3da435f7ca69586fe5853",
      "size": 133534
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:1e8acdaa260712eac85de25745cd44440065e108314a5d02c01a6678d4b75143",
      "size": 779467
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:a812c900745ef51faf67489acb703c178411510edf7e0ab31af973e08567afb0",
      "size": 57201
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:b16bb3b2bd07785f19e8c72faf8106454371bff33191bdb4480fd8d9455b7472",
      "size": 40308
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:b89064556f5a7b35aae658ec0ed7a615ee89caf8ba73d729966234698e5f0eee",
      "size": 124294
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:709a0532f0daa28af616631a44f83f4985cbfbbd57e6d394f621500153a0ce7e",
      "size": 163
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:9eb935637c8e9a7423d3a6f966ab9fed294296b92234eef8e95cc315418e0bcd",
      "size": 147
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:7c3758af1056f8da9dffe70ef11b55d8b30b10af36db88d4baf4b7d7aac25a25",
      "size": 14150560
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:bb7ac849b6bff84e647d9ae4b6bba9ecc4c84e0ceaaa0b1e66a8399d00212cb9",
      "size": 4499894
    }
  ]
}
Digest: sha256:a5789fc40e828c4e7467626e3f69ec5dea8e5da22fe660db8ae6d16f777b0bbf
Command: bazel build @bookworm//base-files/amd64:data_statusd
81.9 KB
Digest: sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e
Command: bazel build @bookworm//netbase/amd64:data_statusd
12.2 KB
Digest: sha256:39dc083afc39bd8dc43d456fe7ff7d39292e593bb2769972c11bb2e5f9119386
Command: bazel build @bookworm//tzdata/amd64:data_statusd
435.3 KB
Digest: sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4
Command: bazel build @bookworm//media-types/amd64:data_statusd
28.3 KB
Digest: sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a
Command: bazel build //common:rootfs
67 bytes
Digest: sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212
Command: bazel build //common:passwd
188 bytes
Digest: sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4
Command: bazel build //common:home
123 bytes
Digest: sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296
Command: bazel build //common:group
162 bytes
Digest: sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112
Command: bazel build //common:tmp
80 bytes
Digest: sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a
Command: bazel build //static:nsswitch
351 bytes
Digest: sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354
Command: bazel build //common:os_release_debian12
314 bytes
Digest: sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b
Command: bazel build //common:cacerts_debian12_amd64
128.8 KB
Digest: sha256:235c3625d753c5b8a741210c2e7fb26b47a0d02cf49acc631a38dcf847eedf89
Command: bazel build @bookworm//libc6/amd64:data_statusd
4.7 MB
Digest: sha256:dc0fb75e565a59a5824baedc9645656d17bc91c4b31332ee179580fa9f60eacd
Command: bazel build @bookworm//libssl3/amd64:data_statusd
2.4 MB
Digest: sha256:336f6c853c4e7eaa77938f48c9b7ce98841916930fb3da435f7ca69586fe5853
Command: bazel build @bookworm//libgomp1/amd64:data_statusd
130.4 KB
Digest: sha256:1e8acdaa260712eac85de25745cd44440065e108314a5d02c01a6678d4b75143
Command: bazel build @bookworm//libstdc++6/amd64:data_statusd
761.2 KB
Digest: sha256:a812c900745ef51faf67489acb703c178411510edf7e0ab31af973e08567afb0
Command: bazel build @bookworm//libgcc-s1/amd64:data_statusd
55.9 KB
Digest: sha256:b16bb3b2bd07785f19e8c72faf8106454371bff33191bdb4480fd8d9455b7472
Command: bazel build @bookworm//gcc-12-base/amd64:data_statusd
39.4 KB
Digest: sha256:b89064556f5a7b35aae658ec0ed7a615ee89caf8ba73d729966234698e5f0eee
Command: COPY /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt # buildkit
121.4 KB
Digest: sha256:709a0532f0daa28af616631a44f83f4985cbfbbd57e6d394f621500153a0ce7e
Command: COPY /tmp/passwd /etc/passwd # buildkit
163 bytes
Digest: sha256:9eb935637c8e9a7423d3a6f966ab9fed294296b92234eef8e95cc315418e0bcd
Command: COPY /tmp/group /etc/group # buildkit
147 bytes
Digest: sha256:7c3758af1056f8da9dffe70ef11b55d8b30b10af36db88d4baf4b7d7aac25a25
Command: COPY /tmp/arc-node-consensus /usr/local/bin/arc-node-consensus # buildkit
13.5 MB
Digest: sha256:bb7ac849b6bff84e647d9ae4b6bba9ecc4c84e0ceaaa0b1e66a8399d00212cb9
Command: COPY /tmp/arc-snapshots /usr/local/bin/arc-snapshots # buildkit
4.3 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE [27000/tcp 29000/tcp]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER arc
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/arc-node-consensus"]
32 bytes
Docker logo
arc-consensus
image amd64 linux
17 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
90 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
13 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
92 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
10 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
3 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
26.6 MB 3 months ago
1769 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
26.7 MB 3 months ago
33 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
75 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
5 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
7 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
0 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
90 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
22 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
2 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
1 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image amd64 linux
2 Uploaded by arc-publisher-gha-service
Docker logo
arc-consensus
image arm64 linux
2 Uploaded by arc-publisher-gha-service

Last scanned

1 month, 2 weeks ago

Scan result

Vulnerable

Vulnerability count

14

Max. severity

Medium
Target: ko52Za0FtcBw.sbom-cyclonedx.json (debian 12.15)
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com cert-portal.siemens.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com cert-portal.siemens.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com cert-portal.siemens.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: gcc-12-base
Installed Version: 12.2.0-14+deb12u1
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2010-4756: glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressions

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: cxib.net securityreason.com securityreason.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2018-20796: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.c

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: www.securityfocus.com access.redhat.com debbugs.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.f5.com www.cve.org
LOW

CVE-2019-1010022: glibc: stack guard protection bypass

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org sourceware.org ubuntu.com www.cve.org
LOW

CVE-2019-1010023: glibc: running ldd on malicious ELF leads to code execution because of wrong size computation

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com ubuntu.com www.cve.org
LOW

CVE-2019-1010024: glibc: ASLR bypass using cache of thread stack and heap

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org
LOW

CVE-2019-1010025: glibc: information disclosure of heap addresses of pthread_created thread

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org
LOW

CVE-2019-9192: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.c

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern

Package Name: libc6
Installed Version: 2.36-9+deb12u14
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org support.f5.com www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libgcc-s1
Installed Version: 12.2.0-14+deb12u1
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libgomp1
Installed Version: 12.2.0-14+deb12u1
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2025-27587: OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable ...

OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.

Package Name: libssl3
Installed Version: 3.0.20-1~deb12u2
Fixed Version:

References: github.com minerva.crocs.fi.muni.cz
LOW

CVE-2026-42767: openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client. Applications that process untrusted CMP/CRMF messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: libssl3
Installed Version: 3.0.20-1~deb12u2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libstdc++6
Installed Version: 12.2.0-14+deb12u1
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull arc-consensus @ reference/tag sha256:e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e:

docker pull docker.cloudsmith.io/circle/arc-network/arc-consensus@sha256:e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e

You can also pull the latest version of this image (if it exists):

docker pull docker.cloudsmith.io/circle/arc-network/arc-consensus:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM docker.cloudsmith.io/circle/arc-network/arc-consensus@sha256:e7e7ad8abb32655d220259e4921a629a244762520849795501d99db9767d3d7e
Top