You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
install-cni
d449cd9d0c6d21205f437e68a89…
One-liner (summary)
Description
This package was uploaded with the following V2 Distribution manifest:
{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":2369,"digest":"sha256:9c92cb106b2f12031a488e9c6a6845eaa7f99197b3153d938fea265b41738924"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":8314924,"digest":"sha256:12a23d347245d7fe433af246cc68fa060316fe912a1b1737b09a86c2c1af6ec8"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":11473896,"digest":"sha256:6b2db426c2c0a50d2b1eae7b0f931802d5caef3c6f963f0faeb88915ff0d0090"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":21046307,"digest":"sha256:8a02d8ee854447231076c712341b341b2f36ea74de8563e44a040ad16f222270"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":39,"digest":"sha256:89732bc7504122601f40269fc9ddfb70982e633ea9caf641ae45736f2846b004"}]}
|
|
install-cni |
1 |
|
||
|
|
install-cni |
1 |
|
||
|
|
install-cni |
2 |
|
||
|
|
install-cni |
18641 |
|
||
|
|
install-cni |
1 |
|
||
|
|
install-cni |
1 |
|
||
|
|
install-cni |
18850 |
|
||
|
|
install-cni |
2 |
|
||
|
|
install-cni |
2 |
|
||
|
|
install-cni |
23 |
|
||
|
|
install-cni |
0 |
|
||
|
|
install-cni |
0 |
|
||
|
|
install-cni |
0 |
|
||
|
|
install-cni |
0 |
|
||
|
|
install-cni |
0 |
|
||
|
|
install-cni |
6 |
|
||
|
|
install-cni |
6 |
|
||
|
|
install-cni |
1 |
|
||
|
|
install-cni |
1 |
|
||
|
|
install-cni |
1 |
|
Last scanned
15 hours ago
Scan result
Vulnerable
Vulnerability count
8
Max. severity
Medium| Target: | 2Ue9c2roHYBD.sbom-cyclonedx.json (redhat 9.8) | |
| MEDIUM |
CVE-2026-56391: coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte inputGNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.Package Name: coreutils-single Installed Version: 8.32-41.el9_8 Fixed Version: References: access.redhat.com cert.pl git.savannah.gnu.org git.savannah.gnu.org nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-56392: coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop valuesGNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35dPackage Name: coreutils-single Installed Version: 8.32-41.el9_8 Fixed Version: References: access.redhat.com cert.pl git.savannah.gnu.org git.savannah.gnu.org nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-54371: attr: Symlink Traversal Privilege Escalation via getfattr and setfattrattr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.Package Name: libattr Installed Version: 2.5.1-3.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com cgit.git.savannah.nongnu.org cgit.git.savannah.nongnu.org nvd.nist.gov security.access.redhat.com www.cve.org www.vulncheck.com |
|
| LOW |
CVE-2021-46195: gcc: uncontrolled recursion in libiberty/rust-demangle.cGCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.Package Name: libgcc Installed Version: 11.5.0-14.el9 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com errata.almalinux.org gcc.gnu.org gcc.gnu.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgcc Installed Version: 11.5.0-14.el9 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: ncurses-base Installed Version: 6.2-12.20210508.el9 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: ncurses-libs Installed Version: 6.2-12.20210508.el9 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loopInteger overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.Package Name: pcre2 Installed Version: 10.40-6.el9 Fixed Version: References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loopInteger overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.Package Name: pcre2-syntax Installed Version: 10.40-6.el9 Fixed Version: References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| Target: | opt/cni/bin/istio-cni | |
| UNKNOWN |
GO-2026-5932: The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesThe golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.Package Name: golang.org/x/crypto Installed Version: v0.54.0 Fixed Version: References: go.dev pkg.go.dev |
|
| Target: | usr/local/bin/install-cni | |
| UNKNOWN |
GO-2026-5932: The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesThe golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.Package Name: golang.org/x/crypto Installed Version: v0.54.0 Fixed Version: References: go.dev pkg.go.dev |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
These instructions assume you have setup the repository first (or read it).
To pull install-cni @ reference/tag sha256:d449cd9d0c6d21205f437e68a8934d39cba8561cfc37796e31112237f59a911d:
docker pull containers.istio.tetratelabs.com/install-cni@sha256:d449cd9d0c6d21205f437e68a8934d39cba8561cfc37796e31112237f59a911d
You can also pull the latest version of this image (if it exists):
docker pull containers.istio.tetratelabs.com/install-cni:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM containers.istio.tetratelabs.com/install-cni@sha256:d449cd9d0c6d21205f437e68a8934d39cba8561cfc37796e31112237f59a911d