Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial

Docker logo envoy  adb982367c146404c488f56b110…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

69.4 MB

Downloads

0

Tags

image amd64 linux

Status  Completed
Checksum (MD5) 67cf1fa9541015f94b02ed1e2a72f16d
Checksum (SHA-1) 107409512ec227ff5a857ea19e29c2f2eeacf4e1
Checksum (SHA-256) adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37
Checksum (SHA-512) 0a415a15099f2c123767b4a79fa6cbcbc6f27c840e477027d7fa6973b49b3cc910…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 3 months ago
Uploaded By tetrate-ci
Slug Id envoy-0633
Unique Id wZSC9hj53f0j
Version (Raw) adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37
Config Digest sha256:259c97d213605413ead4a616a8607dc817f070bf91f7c541ed99cede8980abad
V1 OCI Index Digest sha256:b9a2633c3865bff75e2bdf4461ce4a8391d958fe35e892f25bd4ba2261cd0adf
V1 Distribution (Signed) Digest sha256:2761c15f65d80be077398769402bafa8864d5c0b893ecc608f2dcf9988f5cbf3
V2 Distribution List Digest sha256:03ca2c4bd9adeef5cbdc88ba526ae7e06a09781a5e4f8be3ff065b516ba9625e
V2 Distribution Digest sha256:0fb119f98166823295ac2ea11c720264a5338d97c6a108e83973d6a40c9f9135
V1 Distribution Digest sha256:5d6670611809fd3027b57370de58baed1445a6d53b2f6eaa3ed0fe12634c7d0d
V1 OCI Digest sha256:adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37
  extended metadata
Manifest Type V1 OCI
Architecture amd64
Config
Created 2026-04-23 19:03:12 UTC
Os linux

This package was uploaded with the following V1 OCI manifest:

{
  "schemaVersion": 2,
  "mediaType": "application/vnd.oci.image.manifest.v1+json",
  "config": {
    "mediaType": "application/vnd.oci.image.config.v1+json",
    "digest": "sha256:ccd381e9a94137be5d03caa45036dd6836080eb1f71542957712f365c998660c",
    "size": 5477
  },
  "layers": [
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:526604835308e0d61f64a3d3e2d614308fef4ed655f0111a4566627296c0195c",
      "size": 83843
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e",
      "size": 12481
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:ef49c20a7b35aa995683f311510d35d77e203a2204f84de14a71a6d726e6af73",
      "size": 440802
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4",
      "size": 29005
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a",
      "size": 67
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212",
      "size": 188
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4",
      "size": 123
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296",
      "size": 162
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112",
      "size": 80
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a",
      "size": 351
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354",
      "size": 314
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b",
      "size": 131915
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:c65bb0c25578bf8f2a8b87d1996dfd93a5330c03195c8f0401cf88b2e0de9210",
      "size": 4950300
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:d5ba139b1e9ca7f51be47b37edbb98e31155a1dceab2035bbc03c2331e2a612c",
      "size": 787
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:40e210863c35aa6e85b023657e035904ea52860451e2ab505ed0c4e5fa80b8f1",
      "size": 790
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:00cf20ca87f88914007a775ce242f277d302fb21bf6f76a8fbdc6f089438ef10",
      "size": 30552672
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:372f4e923114ad6ed909da7c839b9447018fc6fa0970e505f1167005aaaaef0c",
      "size": 36612370
    }
  ]
}
Digest: sha256:526604835308e0d61f64a3d3e2d614308fef4ed655f0111a4566627296c0195c
Command: bazel build @bookworm//base-files/amd64:data_statusd
81.9 KB
Digest: sha256:990a9c434e5e0f11549a8d4a41a1991e621b04e30cd63269adbc97b1dc38fd7e
Command: bazel build @bookworm//netbase/amd64:data_statusd
12.2 KB
Digest: sha256:ef49c20a7b35aa995683f311510d35d77e203a2204f84de14a71a6d726e6af73
Command: bazel build @bookworm//tzdata/amd64:data_statusd
430.5 KB
Digest: sha256:bf7a4185f01524837d19abde915ffde84e64368b250f5b5e9f6f75aea62a11d4
Command: bazel build @bookworm//media-types/amd64:data_statusd
28.3 KB
Digest: sha256:2780920e5dbfbe103d03a583ed75345306e572ec5a48cb10361f046767d9f29a
Command: bazel build //common:rootfs
67 bytes
Digest: sha256:7c12895b777bcaa8ccae0605b4de635b68fc32d60fa08f421dc3818bf55ee212
Command: bazel build //common:passwd
188 bytes
Digest: sha256:3214acf345c0cc6bbdb56b698a41ccdefc624a09d6beb0d38b5de0b2303ecaf4
Command: bazel build //common:home
123 bytes
Digest: sha256:52630fc75a18675c530ed9eba5f55eca09b03e91bd5bc15307918bbc1a7e7296
Command: bazel build //common:group
162 bytes
Digest: sha256:dd64bf2dd177757451a98fcdc999a339c35dee5d9872d8f4dc69c8f3c4dd0112
Command: bazel build //common:tmp
80 bytes
Digest: sha256:b839dfae01f66e15c6a8b63520557ed315bdfe036342fa7a0c537259f10d7a9a
Command: bazel build //static:nsswitch
351 bytes
Digest: sha256:dcaa5a89b0ccda4b283e16d0b4d0891cd93d5fe05c6798f7806781a6a2d84354
Command: bazel build //common:os_release_debian12
314 bytes
Digest: sha256:069d1e267530c2e681fbd4d481553b4d05f98082b18fafac86e7f12996dddd0b
Command: bazel build //common:cacerts_debian12_amd64
128.8 KB
Digest: sha256:c65bb0c25578bf8f2a8b87d1996dfd93a5330c03195c8f0401cf88b2e0de9210
Command: bazel build @bookworm//libc6/amd64:data_statusd
4.7 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE [10000/tcp]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/envoy"]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: CMD ["-c" "/etc/envoy/envoy.yaml"]
32 bytes
Digest: sha256:d5ba139b1e9ca7f51be47b37edbb98e31155a1dceab2035bbc03c2331e2a612c
Command: COPY --chown=0:0 --chmod=755 /etc/envoy /etc/envoy # buildkit
787 bytes
Digest: sha256:40e210863c35aa6e85b023657e035904ea52860451e2ab505ed0c4e5fa80b8f1
Command: COPY --chown=0:0 --chmod=644 /etc/envoy/envoy.yaml /etc/envoy/envoy.yaml # buildkit
790 bytes
Digest: sha256:00cf20ca87f88914007a775ce242f277d302fb21bf6f76a8fbdc6f089438ef10
Command: COPY --chown=0:0 --chmod=755 /usr/local/bin/envoy /usr/local/bin/ # buildkit
29.1 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG ENVOY_VARIANT=envoy
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG ENVOY_REVISION=31608367a7f5f7e4ec627f4dac396577f2322fdc
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL vendor=Tetrate.io Inc
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL org.opencontainers.image.title=envoy
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL org.opencontainers.image.source=https://github.com/envoyproxy/envoy.git
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL org.opencontainers.image.revision=31608367a7f5f7e4ec627f4dac396577f2322fdc
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH=amd64
32 bytes
Digest: sha256:372f4e923114ad6ed909da7c839b9447018fc6fa0970e505f1167005aaaaef0c
Command: ADD ./work/envoy/31608367a7f5f7e4ec627f4dac396577f2322fdc/envoy-amd64.tar.gz /usr/local/bin/ # buildkit
34.9 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/envoy"]
32 bytes
Docker logo
envoy
image amd64 linux
16 tetrate-ci
Docker logo
envoy
image amd64 linux
17 tetrate-ci
Docker logo
envoy
image arm64 linux
16 tetrate-ci
Docker logo
envoy
image amd64 linux
18 tetrate-ci
Docker logo
envoy
image arm64 linux
13 tetrate-ci
Docker logo
envoy
image amd64 linux
17 tetrate-ci
Docker logo
envoy
image amd64 linux
19 tetrate-ci
Docker logo
envoy
image arm64 linux
12 tetrate-ci
Docker logo
envoy
image amd64 linux
15 tetrate-ci
Docker logo
envoy
image arm64 linux
13 tetrate-ci
Docker logo
envoy
image amd64 linux
69.4 MB 3 months ago
0 tetrate-ci
Docker logo
envoy
image amd64 linux
0 tetrate-ci
Docker logo
envoy
image arm64 linux
0 tetrate-ci
Docker logo
envoy
image arm64 linux
79.0 MB 3 weeks ago
0 tetrate-ci
Docker logo
envoy
image amd64 linux
1 tetrate-ci
Docker logo
envoy
image amd64 linux
0 tetrate-ci
Docker logo
envoy
image arm64 linux
78.8 MB 2 months ago
1 tetrate-ci
Docker logo
envoy
image arm64 linux
73.1 MB 3 months ago
1 tetrate-ci
Docker logo
envoy
image amd64 linux
72.5 MB 3 months ago
0 tetrate-ci
Docker logo
envoy
image amd64 linux
3 tetrate-ci

Last scanned

3 months ago

Scan result

Vulnerable

Vulnerability count

15

Max. severity

High
Target: wZSC9hj53f0j.sbom-cyclonedx.json (debian 12.13)
HIGH

CVE-2026-0861: glibc: Integer overflow in memalign leads to heap corruption

Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument. This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice. An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org
MEDIUM

CVE-2025-15281: glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org ubuntu.com www.cve.org www.openwall.com
MEDIUM

CVE-2026-0915: glibc: glibc: Information disclosure via zero-valued network query

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org ubuntu.com www.cve.org www.openwall.com
MEDIUM

CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2010-4756: glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressions

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: cxib.net securityreason.com securityreason.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2018-20796: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.c

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: www.securityfocus.com access.redhat.com debbugs.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.f5.com www.cve.org
LOW

CVE-2019-1010022: glibc: stack guard protection bypass

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org sourceware.org ubuntu.com www.cve.org
LOW

CVE-2019-1010023: glibc: running ldd on malicious ELF leads to code execution because of wrong size computation

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com ubuntu.com www.cve.org
LOW

CVE-2019-1010024: glibc: ASLR bypass using cache of thread stack and heap

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: www.securityfocus.com access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org
LOW

CVE-2019-1010025: glibc: information disclosure of heap addresses of pthread_created thread

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com nvd.nist.gov security-tracker.debian.org sourceware.org support.f5.com support.f5.com ubuntu.com www.cve.org
LOW

CVE-2019-9192: glibc: uncontrolled recursion in function check_dst_limits_calc_pos_1 in posix/regexec.c

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern

Package Name: libc6
Installed Version: 2.36-9+deb12u13
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org support.f5.com www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull envoy @ reference/tag sha256:adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37:

docker pull containers.istio.tetratelabs.com/envoy@sha256:adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/envoy:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/envoy@sha256:adb982367c146404c488f56b110c9e2387f695c02249f65dd9b3b86b4afa1a37
Top