Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tetrate tetrate (Tetrate) / getistio-containers
Tetrate Istio Distro project (formerly GetIstio) container images registry

Docker logo istioctl  51a5b9f208f0b141b4526736eb8…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

118.8 MB

Downloads

0

Tags

new image arm64 linux

Status  Completed
Checksum (MD5) a45ca5387c4dbd28ca0633c20c31665b
Checksum (SHA-1) 31cfee5e3a4aa72bcbc86c0eed49c3277a834bbe
Checksum (SHA-256) 51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e
Checksum (SHA-512) 643adba5105220d4a0e2f5ad20674ffdaf91aaedfe6039ac627c1b6f2c9a9c2790…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 9 hours ago
Uploaded By tetrate-ci
Slug Id istioctl-s90i
Unique Id nBWsidYZMm2g
Version (Raw) 51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e
Config Digest sha256:1712344efb1b0cded0b994171bc2437abd7e9870e242911b4551626dba9d282a
V1 OCI Index Digest sha256:2c5baf7ff926c13f8ddfc550e3e0e7e601ff8f29645ea8e2182ada5ed5af9c9e
V1 Distribution (Signed) Digest sha256:d4edc8119c6c26793ff4e66ca753dcaa86e518d6e125a34592bd9601f96073a8
V1 OCI Digest sha256:61012de68884bcdaed309a8e8801e4cdf4d80251ac3fed884600bf7dad4a29fd
V2 Distribution List Digest sha256:4e1353facd4438ca22090d999513b884d86d9ddabd413955ad5946c85c26a0b9
V1 Distribution Digest sha256:e29750fea6bda7e85dca74bf06b3cd258f5a19ef9be57541209be2e77058caf2
V2 Distribution Digest sha256:51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Config
Created 2026-07-31 02:04:46 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":3615,"digest":"sha256:b91b85a528e69d275eeed20b984285cecbf64956a2f692defaef40057f335ff3"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":32797255,"digest":"sha256:806651ee6a7e15d8d2085ab984a7121e939d4d97efb680613a8e421defa42f5e"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":51993138,"digest":"sha256:94d47721c1f66bbbecd6dc42f8bb01dae9c1c51d4b23421fe6234f3cbf316779"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":10901725,"digest":"sha256:62db9bd79177fc2da6687ee6f97fb8769ae15a60ee0da2e372add905b18a009f"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":4913,"digest":"sha256:5f497ae9b773b5b0de355448f622446dd41ac423f29712d09278edd91f649f03"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":28876331,"digest":"sha256:38608fecc70e3fa6318fbdbf007f20674b8e1913ee7250b33002da67b5c859ce"}]}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=24.04
32 bytes
Digest: sha256:806651ee6a7e15d8d2085ab984a7121e939d4d97efb680613a8e421defa42f5e
Command: /bin/sh -c #(nop) ADD file:cdc9a547b921f36a32310f732815bbee6c6e4f5bd768ab5d49cdc0aa1b9f4785 in /
31.3 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"]
32 bytes
Digest: sha256:94d47721c1f66bbbecd6dc42f8bb01dae9c1c51d4b23421fe6234f3cbf316779
Command: RUN /bin/sh -c apt update && apt upgrade -y # buildkit
49.6 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV DEBIAN_FRONTEND=noninteractive
32 bytes
Digest: sha256:62db9bd79177fc2da6687ee6f97fb8769ae15a60ee0da2e372add905b18a009f
Command: RUN /bin/sh -c apt-get update && apt-get install --no-install-recommends -y ca-certificates curl iptables nftables iproute2 iputils-ping knot-dnsutils netcat-openbsd tcpdump conntrack bsdmainutils net-tools lsof sudo && update-ca-certificates && apt-get upgrade -y && apt-get clean && rm -rf /var/log/*log /var/lib/apt/lists/* /var/log/apt/* /var/lib/dpkg/*-old /var/cache/debconf/*-old && update-alternatives --set iptables /usr/sbin/iptables-legacy && update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy # buildkit
10.4 MB
Digest: sha256:5f497ae9b773b5b0de355448f622446dd41ac423f29712d09278edd91f649f03
Command: RUN /bin/sh -c useradd -m --uid 1337 istio-proxy && echo "istio-proxy ALL=NOPASSWD: ALL" >> /etc/sudoers # buildkit
4.8 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER 1000:1000
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:38608fecc70e3fa6318fbdbf007f20674b8e1913ee7250b33002da67b5c859ce
Command: COPY arm64/istioctl /usr/local/bin/istioctl # buildkit
27.5 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/istioctl"]
32 bytes
Docker logo
istioctl
image arm64 linux
1 tetrate-ci
Docker logo
istioctl
image amd64 linux
2 tetrate-ci
Docker logo
istioctl
image amd64 linux
1 tetrate-ci
Docker logo
istioctl
image amd64 linux
71.1 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
66.2 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
28.2 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image amd64 linux
118.1 MB 1 month ago
2 tetrate-ci
Docker logo
istioctl
image amd64 linux
77.5 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
72.1 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image amd64 linux
121.4 MB 1 month ago
0 tetrate-ci
Docker logo
istioctl
new image arm64 linux
118.8 MB 9 hours ago
0 tetrate-ci
Docker logo
istioctl
new image amd64 linux
122.6 MB 9 hours ago
0 tetrate-ci
Docker logo
istioctl
image amd64 linux
113.0 MB 1 week ago
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
109.9 MB 1 week ago
0 tetrate-ci
Docker logo
istioctl
image amd64 linux
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
1 tetrate-ci
Docker logo
istioctl
image amd64 linux
31.6 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
117.1 MB 1 month ago
1 tetrate-ci
Docker logo
istioctl
image arm64 linux
72.7 MB 1 month ago
1 tetrate-ci

Last scanned

9 hours ago

Scan result

Vulnerable

Vulnerability count

11

Max. severity

Medium
Target: nBWsidYZMm2g.sbom-cyclonedx.json (ubuntu 24.04)
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: bsdextrautils
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: bsdutils
Installed Version: 1:2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libblkid1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-22185: OpenLDAP: OpenLDAP LMDB: Denial of Service and Information Disclosure via Heap Buffer Underflow

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

Package Name: liblmdb0
Installed Version: 0.9.31-1build1
Fixed Version:

References: access.redhat.com bugs.openldap.org nvd.nist.gov seclists.org seclists.org www.cve.org www.openldap.org www.vulncheck.com
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libmount1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-13757: p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

Package Name: libp11-kit0
Installed Version: 0.25.3-4ubuntu2.1
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libsmartcols1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: libuuid1
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: mount
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devices

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Package Name: util-linux
Installed Version: 2.39.3-9ubuntu6.5
Fixed Version:

References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2025-29481: libbpf: Heap Buffer Overflow in libbpf

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

Package Name: libbpf1
Installed Version: 1:1.3.0-2build2
Fixed Version:

References: access.redhat.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2025-1352: elfutils: GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com cert-portal.siemens.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2025-1376: elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com cert-portal.siemens.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2024-2236: libgcrypt: vulnerable to Marvin Attack

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Package Name: libgcrypt20
Installed Version: 1.10.3-2ubuntu0.1
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org dev.gnupg.org errata.almalinux.org errata.rockylinux.org github.com gitlab.com linux.oracle.com linux.oracle.com lists.gnupg.org nvd.nist.gov www.cve.org
LOW

CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger command

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

Package Name: libsystemd0
Installed Version: 255.4-1ubuntu8.16
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com
LOW

CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger command

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

Package Name: libudev1
Installed Version: 255.4-1ubuntu8.16
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: login
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: passwd
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2026-27171: zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

Package Name: zlib1g
Installed Version: 1:1.3.dfsg-3.1ubuntu2.1
Fixed Version:

References: 7asecurity.com 7asecurity.com 7asecurity.com access.redhat.com github.com github.com github.com nvd.nist.gov ostif.org ostif.org www.cve.org
Target: usr/local/bin/istioctl
UNKNOWN

GO-2026-5932: The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.

Package Name: golang.org/x/crypto
Installed Version: v0.54.0
Fixed Version:

References: go.dev pkg.go.dev

These instructions assume you have setup the repository first (or read it).

To pull istioctl @ reference/tag sha256:51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e:

docker pull containers.istio.tetratelabs.com/istioctl@sha256:51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/istioctl:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/istioctl@sha256:51a5b9f208f0b141b4526736eb80a4837062dab8a3e6d264656e16c6e1fb391e
Top