Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tetrate tetrate (Tetrate) / getistio-containers
Tetrate Istio Distro project (formerly GetIstio) container images registry

Docker logo install-cni  5097caa83ab94c587466f3908e7…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

118.5 MB

Downloads

18886

Tags

image arm64 linux

Status  Completed
Checksum (MD5) 16c8771bc02de77848b95729d6312fde
Checksum (SHA-1) 8a9b09384532dc7855bc070edbb672324f440898
Checksum (SHA-256) 5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763
Checksum (SHA-512) dd10854832d0442468c9b5bc3f55cf52f798f755d2951e0e662e4c22af10935971…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 2 months ago
Uploaded By tetrate-ci
Slug Id install-cni-z3gi
Unique Id 7cRLrPkVIxnB
Version (Raw) 5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763
Config Digest sha256:5d4c0d1c21d58306f5953ecbcb6f0dda538db51f705e0adc4d7020011257104d
V1 OCI Index Digest sha256:17d49990de87ce0dc41dbafb9d9b4cb73afcf136e188f59ff329873c16421212
V1 Distribution (Signed) Digest sha256:f91ef0b12a67d69ae37c4310c145fc084f9655a20c91cd4a48b7c481b555f922
V1 OCI Digest sha256:8c14399105b2bd768d30c417011d00efdf78a277e6e7b2c4c117f17396e2cd35
V2 Distribution List Digest sha256:7bb97c653df180a76d0ba24e3bd37dc1044c5c44c7401987219a2d3d39f2ba7b
V1 Distribution Digest sha256:977f63e4b47ae06824bcfe72003e04f58307e78650adb798b729bad4f6b25ca3
V2 Distribution Digest sha256:5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Config
Created 2026-05-22 01:05:04 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":4343,"digest":"sha256:044d9dcc2d728e5b53db163362d00507719a75fa3c8157af80a2a1d7655ddc40"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":32792863,"digest":"sha256:fc6c982542b6b86a2434590374dc6d2c344556e2444a569f698c0db71ca93414"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":48205827,"digest":"sha256:5905cb5b35e201cf6b41c4cfd067d19b669d33fbd62a288369e34a6dad36cc99"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":10953944,"digest":"sha256:59f12d21685a9ba640735ab6c96a9aeff574ed9b7971dfe9bd4e0a04dd598731"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":4920,"digest":"sha256:34b818d08b634ef0604c5249ae52690a7a11ecc7f3cc8bde7175b7c6e14d29e3"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":11408658,"digest":"sha256:b6118542b1d99cad6501df2a414ff6bd6e5c18c4e0a7f289ee9c0f10a529ca5a"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":20863851,"digest":"sha256:64740b00e5ab4187b75289e45acfe1e2ea52d36359a0d128d005676b67650c53"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":39,"digest":"sha256:89732bc7504122601f40269fc9ddfb70982e633ea9caf641ae45736f2846b004"}]}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=24.04
32 bytes
Digest: sha256:fc6c982542b6b86a2434590374dc6d2c344556e2444a569f698c0db71ca93414
Command: /bin/sh -c #(nop) ADD file:c98b7645109cdf61ab97492b90629581b1b7cb925b9d58a5787a4aaeb719f2be in /
31.3 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"]
32 bytes
Digest: sha256:5905cb5b35e201cf6b41c4cfd067d19b669d33fbd62a288369e34a6dad36cc99
Command: RUN /bin/sh -c apt update && apt upgrade -y # buildkit
46.0 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV DEBIAN_FRONTEND=noninteractive
32 bytes
Digest: sha256:59f12d21685a9ba640735ab6c96a9aeff574ed9b7971dfe9bd4e0a04dd598731
Command: RUN /bin/sh -c apt-get update && apt-get install --no-install-recommends -y ca-certificates curl iptables nftables iproute2 iputils-ping knot-dnsutils netcat-openbsd tcpdump conntrack bsdmainutils net-tools lsof sudo && update-ca-certificates && apt-get upgrade -y && apt-get clean && rm -rf /var/log/*log /var/lib/apt/lists/* /var/log/apt/* /var/lib/dpkg/*-old /var/cache/debconf/*-old && update-alternatives --set iptables /usr/sbin/iptables-legacy && update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy # buildkit
10.4 MB
Digest: sha256:34b818d08b634ef0604c5249ae52690a7a11ecc7f3cc8bde7175b7c6e14d29e3
Command: RUN /bin/sh -c useradd -m --uid 1337 istio-proxy && echo "istio-proxy ALL=NOPASSWD: ALL" >> /etc/sudoers # buildkit
4.8 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL description=Istio CNI plugin installer.
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:b6118542b1d99cad6501df2a414ff6bd6e5c18c4e0a7f289ee9c0f10a529ca5a
Command: COPY arm64/istio-cni /opt/cni/bin/istio-cni # buildkit
10.9 MB
Digest: sha256:64740b00e5ab4187b75289e45acfe1e2ea52d36359a0d128d005676b67650c53
Command: COPY arm64/install-cni /usr/local/bin/install-cni # buildkit
19.9 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/cni/bin
32 bytes
Digest: sha256:89732bc7504122601f40269fc9ddfb70982e633ea9caf641ae45736f2846b004
Command: WORKDIR /opt/cni/bin
39 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: CMD ["/usr/local/bin/install-cni"]
32 bytes
Docker logo
install-cni
image arm64 linux
4 tetrate-ci
Docker logo
install-cni
image amd64 linux
4 tetrate-ci
Docker logo
install-cni
image amd64 linux
0 tetrate-ci
Docker logo
install-cni
image arm64 linux
0 tetrate-ci
Docker logo
install-cni
image arm64 linux
5 tetrate-ci
Docker logo
install-cni
image amd64 linux
0 tetrate-ci
Docker logo
install-cni
image amd64 linux
0 tetrate-ci
Docker logo
install-cni
image arm64 linux
38.9 MB 4 weeks ago
1 tetrate-ci
Docker logo
install-cni
image amd64 linux
44.3 MB 4 weeks ago
1 tetrate-ci
Docker logo
install-cni
image amd64 linux
43.2 MB 4 weeks ago
1 tetrate-ci
Docker logo
install-cni
image arm64 linux
118.5 MB 2 months ago
18886 tetrate-ci
Docker logo
install-cni
image amd64 linux
2 tetrate-ci
Docker logo
install-cni
image arm64 linux
1 tetrate-ci
Docker logo
install-cni
image amd64 linux
5 tetrate-ci
Docker logo
install-cni
image arm64 linux
2 tetrate-ci
Docker logo
install-cni
image arm64 linux
0 tetrate-ci
Docker logo
install-cni
image amd64 linux
43.8 MB 4 weeks ago
1 tetrate-ci
Docker logo
install-cni
image arm64 linux
39.2 MB 4 weeks ago
1 tetrate-ci
Docker logo
install-cni
image amd64 linux
42.7 MB 4 weeks ago
1 tetrate-ci
Docker logo
install-cni
image arm64 linux
75.6 MB 4 weeks ago
21 tetrate-ci

Last scanned

2 months ago

Scan result

Vulnerable

Vulnerability count

26

Max. severity

High
Target: 7cRLrPkVIxnB.sbom-cyclonedx.json (ubuntu 24.04)
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: bsdextrautils
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: bsdutils
Installed Version: 1:2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libblkid1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Package Name: libc-bin
Installed Version: 2.39-0ubuntu8.7
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: libc-bin
Installed Version: 2.39-0ubuntu8.7
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: libc-bin
Installed Version: 2.39-0ubuntu8.7
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Package Name: libc6
Installed Version: 2.39-0ubuntu8.7
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: libc6
Installed Version: 2.39-0ubuntu8.7
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: libc6
Installed Version: 2.39-0ubuntu8.7
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-33845: gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-33846: gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-3832: gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com access.redhat.com bugzilla.redhat.com gitlab.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-3833: gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com access.redhat.com bugzilla.redhat.com gitlab.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42009: gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42010: gnutls: gnutls: Authentication Bypass via NUL Character in Username

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42011: gnutls: gnutls: Security bypass due to incorrect name constraint handling

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: access.redhat.com access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42012

Certificates containing URI or SRV Subject Alternative Names would fall back to checking DNS hostnames against Common Name, allowing potential misuse of such certificates beyond their original purpose.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42013

Validation of certificates with oversized Subject Alternative Names would fall back to checking DNS hostnames against Common Name.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42014

Changing the Security Officer PIN with gnutls_pkcs11_token_set_pin() with oldpin == NULL for a token lacking a protected authentication path led to a use-after-free.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-42015

Appending to a PKCS#12 bag that already contained 32 elements could write past the bag's internal array.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-5260

For a server using an RSA key backed by a PKCS#11 token, a client sending an extremely short premaster secret during an RSA key exchange could trigger a short heap overread.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-5419

The PKCS#7 padding check performed during decryption was not constant-time, potentially leaking information about the padding bytes through timing differences.

Package Name: libgnutls30t64
Installed Version: 3.8.3-1.1ubuntu3.5
Fixed Version: 3.8.3-1.1ubuntu3.6

References: ubuntu.com www.cve.org www.gnutls.org
MEDIUM

CVE-2026-22185: OpenLDAP: OpenLDAP LMDB: Denial of Service and Information Disclosure via Heap Buffer Underflow

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

Package Name: liblmdb0
Installed Version: 0.9.31-1build1
Fixed Version:

References: access.redhat.com bugs.openldap.org nvd.nist.gov seclists.org seclists.org www.cve.org www.openldap.org www.vulncheck.com
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libmount1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libsmartcols1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libuuid1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: mount
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-45582: tar: Tar path traversal

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which "tar xf" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each "tar xf" in its Security Rules of Thumb; however, third-party advice leads users to run "tar xf" more than once into the same directory.

Package Name: tar
Installed Version: 1.35+dfsg-3build1
Fixed Version:

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com lists.gnu.org nvd.nist.gov www.cve.org www.gnu.org www.gnu.org www.gnu.org www.gnu.org
MEDIUM

CVE-2026-5704: tar: tar: Hidden file injection via crafted archives

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Package Name: tar
Installed Version: 1.35+dfsg-3build1
Fixed Version:

References: www.openwall.com www.openwall.com www.openwall.com access.redhat.com bugzilla.redhat.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: util-linux
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2025-29481: libbpf: Heap Buffer Overflow in libbpf

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

Package Name: libbpf1
Installed Version: 1:1.3.0-2build2
Fixed Version:

References: access.redhat.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2025-1352: elfutils: GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2025-1376: elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2024-2236: libgcrypt: vulnerable to Marvin Attack

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Package Name: libgcrypt20
Installed Version: 1.10.3-2build1
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org dev.gnupg.org errata.almalinux.org errata.rockylinux.org github.com gitlab.com linux.oracle.com linux.oracle.com lists.gnupg.org nvd.nist.gov www.cve.org
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: login
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: passwd
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
Target: opt/cni/bin/istio-cni
HIGH

CVE-2026-35469: Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

Package Name: github.com/moby/spdystream
Installed Version: v0.5.0
Fixed Version: 0.5.1

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
Target: usr/local/bin/install-cni
HIGH

CVE-2026-35469: Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

Package Name: github.com/moby/spdystream
Installed Version: v0.5.0
Fixed Version: 0.5.1

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull install-cni @ reference/tag sha256:5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763:

docker pull containers.istio.tetratelabs.com/install-cni@sha256:5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/install-cni:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/install-cni@sha256:5097caa83ab94c587466f3908e72f2a73263c67790c0223e2203204140e37763
Top