You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
Nix,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
arc-execution
45a0f17442ae29488a8516a8a47…
One-liner (summary)
Description
| Status | Completed |
|---|---|
| Checksum (MD5) | 8f8cfc45dcef07e572229ae06537bd69 |
| Checksum (SHA-1) | f2cb3b431ebd09dc29a2c8eee494675c5d5661dc |
| Checksum (SHA-256) | 45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606 |
| Checksum (SHA-512) | bb02b8260aca34633e7280aca871ea8ec1c71981fc837347c2686605bf25a6e432… |
| GPG Signature | |
| GPG Fingerprint | 2006bcbaea44c3d0630ff4e132ef04c02d67714a |
| Storage Region | Ohio, United States |
| Type | Binary (contains binaries and binary artifacts) |
| Uploaded At | 1 week, 1 day ago |
| Uploaded By |
|
| Slug Id | arc-execution-hka7 |
| Unique Id | lZBA2lEwcqZI |
| Version (Raw) | 45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606 |
| Version (Parsed) |
|
| docker-specific metadata | |
| Image Digest | sha256:45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606 |
| Config Digest | sha256:f1304c0140c6f2f97351e7f23ec2aa8b7511674b4a91283d6862f18f456adbb1 |
| V1 OCI Index Digest | sha256:a5e3d94e6b41429a7e06e8891a67d2ed81950c37c10bcd4fb32733caffdecf6e |
| V1 Distribution (Signed) Digest | sha256:ef522aabee3178b95a47d4bc66ef29af799de7a938608e9068f1f9fa2872a961 |
| V2 Distribution List Digest | sha256:5b6ab47450cd3176e57f09ce9574d64f53794056b39c792224b2fbb0ffe9012b |
| V2 Distribution Digest | sha256:e35b3d98f1f3e1ebab1039bee3305fd3cedb5c495b99fd7e453c6862e0bbbbda |
| V1 Distribution Digest | sha256:1addd3bd32108beee42ba9bcd8004d512fd85a21cedb94752ee82d4eb315e0a7 |
| V1 OCI Digest | sha256:45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606 |
| extended metadata | |
| Manifest Type | V1 OCI |
| Architecture | amd64 |
| Config | |
| Created | 2026-08-28 11:13:33 UTC |
| Os | linux |
This package was uploaded with the following V1 OCI manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.oci.image.manifest.v1+json",
"config": {
"mediaType": "application/vnd.oci.image.config.v1+json",
"digest": "sha256:b8e946cd3674d5f3afe8d9a5e3c45630fe07b89511e4896b08a0a725819ac8a0",
"size": 5052
},
"layers": [
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:a5789fc40e828c4e7467626e3f69ec5dea8e5da22fe660db8ae6d16f777b0bbf",
"size": 83900
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e",
"size": 12481
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:39dc083afc39bd8dc43d456fe7ff7d39292e593bb2769972c11bb2e5f9119386",
"size": 445709
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4",
"size": 29005
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a",
"size": 67
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212",
"size": 188
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4",
"size": 123
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296",
"size": 162
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112",
"size": 80
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a",
"size": 351
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354",
"size": 314
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:96ed2737ae312e0bc637b40783f7c2f23416cb72ca957aa01855f1614278e64b",
"size": 143347
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:235c3625d753c5b8a741210c2e7fb26b47a0d02cf49acc631a38dcf847eedf89",
"size": 4951123
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:dc0fb75e565a59a5824baedc9645656d17bc91c4b31332ee179580fa9f60eacd",
"size": 2506537
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:336f6c853c4e7eaa77938f48c9b7ce98841916930fb3da435f7ca69586fe5853",
"size": 133534
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:1e8acdaa260712eac85de25745cd44440065e108314a5d02c01a6678d4b75143",
"size": 779467
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:a812c900745ef51faf67489acb703c178411510edf7e0ab31af973e08567afb0",
"size": 57201
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:b16bb3b2bd07785f19e8c72faf8106454371bff33191bdb4480fd8d9455b7472",
"size": 40308
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:ad96eb3751e5391764db6bf516bbb7633dc1e9aae914a47a0a27be2dccfe63bd",
"size": 124295
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:c9d9ba4236a3092f006e70fd9383969a44731c44bb2c4e108f5bfc4df9aced7b",
"size": 162
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:96d7882ce24192a8649a626613aa6343144e1a15fac756b50cbff85720bde66f",
"size": 147
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:1a7dce92a043125b0d54c039c4345be6c23afa7f68a3235b34e3c69d3f7501f8",
"size": 34885661
},
{
"mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
"digest": "sha256:b737741be5e0a73915da7ae1c619a046589322884bac24e167f424e3f7372df8",
"size": 5106443
}
]
}
|
Digest:
sha256:a5789fc40e828c4e7467626e3f69ec5dea8e5da22fe660db8ae6d16f777b0bbf
Command: bazel build @bookworm//base-files/amd64:data_statusd |
81.9 KB | ||
|
Digest:
sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e
Command: bazel build @bookworm//netbase/amd64:data_statusd |
12.2 KB | ||
|
Digest:
sha256:39dc083afc39bd8dc43d456fe7ff7d39292e593bb2769972c11bb2e5f9119386
Command: bazel build @bookworm//tzdata/amd64:data_statusd |
435.3 KB | ||
|
Digest:
sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4
Command: bazel build @bookworm//media-types/amd64:data_statusd |
28.3 KB | ||
|
Digest:
sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a
Command: bazel build //common:rootfs |
67 bytes | ||
|
Digest:
sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212
Command: bazel build //common:passwd |
188 bytes | ||
|
Digest:
sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4
Command: bazel build //common:home |
123 bytes | ||
|
Digest:
sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296
Command: bazel build //common:group |
162 bytes | ||
|
Digest:
sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112
Command: bazel build //common:tmp |
80 bytes | ||
|
Digest:
sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a
Command: bazel build //static:nsswitch |
351 bytes | ||
|
Digest:
sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354
Command: bazel build //common:os_release_debian12 |
314 bytes | ||
|
Digest:
sha256:96ed2737ae312e0bc637b40783f7c2f23416cb72ca957aa01855f1614278e64b
Command: bazel build //common:cacerts_debian12_amd64_tar |
140.0 KB | ||
|
Digest:
sha256:235c3625d753c5b8a741210c2e7fb26b47a0d02cf49acc631a38dcf847eedf89
Command: bazel build @bookworm//libc6/amd64:data_statusd |
4.7 MB | ||
|
Digest:
sha256:dc0fb75e565a59a5824baedc9645656d17bc91c4b31332ee179580fa9f60eacd
Command: bazel build @bookworm//libssl3/amd64:data_statusd |
2.4 MB | ||
|
Digest:
sha256:336f6c853c4e7eaa77938f48c9b7ce98841916930fb3da435f7ca69586fe5853
Command: bazel build @bookworm//libgomp1/amd64:data_statusd |
130.4 KB | ||
|
Digest:
sha256:1e8acdaa260712eac85de25745cd44440065e108314a5d02c01a6678d4b75143
Command: bazel build @bookworm//libstdc++6/amd64:data_statusd |
761.2 KB | ||
|
Digest:
sha256:a812c900745ef51faf67489acb703c178411510edf7e0ab31af973e08567afb0
Command: bazel build @bookworm//libgcc-s1/amd64:data_statusd |
55.9 KB | ||
|
Digest:
sha256:b16bb3b2bd07785f19e8c72faf8106454371bff33191bdb4480fd8d9455b7472
Command: bazel build @bookworm//gcc-12-base/amd64:data_statusd |
39.4 KB | ||
|
Digest:
sha256:ad96eb3751e5391764db6bf516bbb7633dc1e9aae914a47a0a27be2dccfe63bd
Command: COPY /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt # buildkit |
121.4 KB | ||
|
Digest:
sha256:c9d9ba4236a3092f006e70fd9383969a44731c44bb2c4e108f5bfc4df9aced7b
Command: COPY /tmp/passwd /etc/passwd # buildkit |
162 bytes | ||
|
Digest:
sha256:96d7882ce24192a8649a626613aa6343144e1a15fac756b50cbff85720bde66f
Command: COPY /tmp/group /etc/group # buildkit |
147 bytes | ||
|
Digest:
sha256:1a7dce92a043125b0d54c039c4345be6c23afa7f68a3235b34e3c69d3f7501f8
Command: COPY /tmp/arc-node-execution /usr/local/bin/arc-node-execution # buildkit |
33.3 MB | ||
|
Digest:
sha256:b737741be5e0a73915da7ae1c619a046589322884bac24e167f424e3f7372df8
Command: COPY /tmp/arc-snapshots /usr/local/bin/arc-snapshots # buildkit |
4.9 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE [6061/tcp 8545/tcp 8546/tcp 8551/tcp 9001/tcp] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER arc |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/arc-node-execution"] |
32 bytes |
|
|
arc-execution |
100 |
|
||
|
|
arc-execution |
11 |
|
||
|
|
arc-execution |
18 |
|
||
|
|
arc-execution |
1889 |
|
||
|
|
arc-execution |
35 |
|
||
|
|
arc-execution |
10 |
|
||
|
|
arc-execution |
0 |
|
||
|
|
arc-execution |
93 |
|
||
|
|
arc-execution |
1 |
|
||
|
|
arc-execution |
82 |
|
||
|
|
arc-execution |
15 |
|
||
|
|
arc-execution |
1 |
|
||
|
|
arc-execution |
85 |
|
||
|
|
arc-execution |
21 |
|
||
|
|
arc-execution |
22 |
|
||
|
|
arc-execution |
2 |
|
||
|
|
arc-execution |
2 |
|
||
|
|
arc-execution |
1 |
|
Last scanned
1 week, 1 day ago
Scan result
Vulnerable
Vulnerability count
26
Max. severity
Medium| Target: | lZBA2lEwcqZI.sbom-cyclonedx.json (debian 12.15) | |
| MEDIUM |
CVE-2026-19499: glibc: Buffer Overflow in strfmon right-justification paddingA flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-19542: glibc: Fix out-of-bounds array write in tdeleteA flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processingThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large widthCalling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodingsCalling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS responseThe deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-6368: glibc: glibc: Process abort due to invalid memory in wordexpCalling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-6791: glibc: Glibc: Denial of Service via stack exhaustion during tilde expansionWhen expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-77117: glibc: Non-progress DoS in SHIFT_JISX0213 ->A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-63072: openssl: heap buffer overflow in CMS key unwrappingIssue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure. The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation. FIPS impact: no As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org |
|
| MEDIUM |
CVE-2026-63076: openssl: invalid pointer dereference in CMP server via crafted protectionAlgIssue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: gcc-12-base Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2010-4756: glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressionsThe glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: cxib.net securityreason.com securityreason.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com nvd.nist.gov security.netapp.com www.cve.org |
|
| LOW |
CVE-2018-20796: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.cIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.securityfocus.com access.redhat.com debbugs.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.f5.com www.cve.org |
|
| LOW |
CVE-2019-1010022: glibc: stack guard protection bypassGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org sourceware.org ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010023: glibc: running ldd on malicious ELF leads to code execution because of wrong size computationGNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010024: glibc: ASLR bypass using cache of thread stack and heapGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-1010025: glibc: information disclosure of heap addresses of pthread_created threadGNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2019-9192: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.cIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted patternPackage Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: access.redhat.com nvd.nist.gov sourceware.org support.f5.com www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgcc-s1 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgomp1 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2025-27587: OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable ...OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: github.com minerva.crocs.fi.muni.cz |
|
| LOW |
CVE-2026-42767: openssl: NULL Pointer Dereference in CRMF EncryptedValue DecryptionIssue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client. Applications that process untrusted CMP/CRMF messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com github.com github.com github.com github.com github.com github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-54874: openssl: excessive memory use buffering DTLS records for a future epochIssue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service. CWE: CWE-405: Asymmetric Resource Consumption (Amplification) Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up. Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network. An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22. Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell. -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt CaswellPackage Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-63074: openssl: CMP indefinite cache growth of ExtraCertsIssue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth. Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack. This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely. The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-75803: Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ...Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages. CWE: CWE-354 (Improper Validation of Integrity Check Value) Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case. FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module.Package Name: libssl3 Installed Version: 3.0.20-1~deb12u2 Fixed Version: References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libstdc++6 Installed Version: 12.2.0-14+deb12u1 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| UNKNOWN |
CVE-2026-18374: Passing an effectively empty string to the `,ccs=` syntax extension of ...Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: www.openwall.com sourceware.org sourceware.org |
|
| UNKNOWN |
CVE-2026-80489Package Name: libc6 Installed Version: 2.36-9+deb12u14 Fixed Version: References: |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
These instructions assume you have setup the repository first (or read it).
To pull arc-execution @ reference/tag sha256:45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606:
docker pull docker.cloudsmith.io/circle/arc-network/arc-execution@sha256:45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606
You can also pull the latest version of this image (if it exists):
docker pull docker.cloudsmith.io/circle/arc-network/arc-execution:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.cloudsmith.io/circle/arc-network/arc-execution@sha256:45a0f17442ae29488a8516a8a47f5ae368da75a0ef9bcc56873615eda1312606