Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tetrate tetrate (Tetrate) / getistio-containers
Tetrate Istio Distro project (formerly GetIstio) container images registry

Docker logo pilot  71b0253b82e20ce00bb6ba679c6…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

118.8 MB

Downloads

0

Tags

image arm64 linux

Status  Completed
Checksum (MD5) 2282e8ec2d8989425654e84e17bf5a6e
Checksum (SHA-1) 925923d90c58cdbd661a24dfd91215300c7dec92
Checksum (SHA-256) 71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef
Checksum (SHA-512) d1d436e5d336bdfe3da24e2c0f9e68ffae01e751cc318973b9deeabc044a1bec80…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 3 months, 2 weeks ago
Uploaded By tetrate-ci
Slug Id pilot-k4vn
Unique Id ErdSbZFByeRm
Version (Raw) 71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef
Config Digest sha256:a7018e2e07d425f0d4298a5bbf7ae34f63482b3a2fcd6b9e3cd41fa7042e603c
V1 OCI Index Digest sha256:ca7dba2090f8ac43944aed047ae155160276eb25c79785bb9b6a5172991c809b
V1 Distribution (Signed) Digest sha256:33124b9fee6f9f250bc62591e1f13974e2dab604d7c35f9c86b83cc2e56ef7d7
V1 OCI Digest sha256:7f8437cf497610d75f072cedf4e66786e891a9bddd4d1683b9e69f77cde3d684
V2 Distribution List Digest sha256:e4f9d6da2c69952e05c567bc50c1fc3d72240839aacb29a117ce868d0eeccbb3
V1 Distribution Digest sha256:feea9b55048845976f15d09338dd27e5c950b64d6e0bf58e8ea377777ae11945
V2 Distribution Digest sha256:71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Config
Created 2026-04-09 04:06:42 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":3825,"digest":"sha256:7f3e5d99dd576b0dc8df28b47cf27c0d05a90b88f1229c30fa266f0de972f92f"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":32756544,"digest":"sha256:4da068ac31b6f8f330cbc3011c3037e0e11e1a98e1cc8fac27b8a78ed04dfdd7"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":51525667,"digest":"sha256:8f3741df09e005c3190df68034f58fca68a150cbf49a1bd9998668b2a8eada0e"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":10465680,"digest":"sha256:cf10bea649ffd16a8f20b8bf7133d1b3b5e113f7d3b9652523011f437c66894f"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":4922,"digest":"sha256:3eddda9fe510a9d71a57fcf2ff230cf59f121c2d30c18a4b143ce376ae22b5f7"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":29784588,"digest":"sha256:26def7dccab085548ae76fd91ed812a36986168f226cca7e5cc4f585d607c81a"}]}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.ref.name=ubuntu
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=24.04
32 bytes
Digest: sha256:4da068ac31b6f8f330cbc3011c3037e0e11e1a98e1cc8fac27b8a78ed04dfdd7
Command: /bin/sh -c #(nop) ADD file:2763d61bc43bd178306ae0d4151c2477166ebf199b8d7294d9ea410f9891993f in /
31.2 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"]
32 bytes
Digest: sha256:8f3741df09e005c3190df68034f58fca68a150cbf49a1bd9998668b2a8eada0e
Command: RUN /bin/sh -c apt update && apt upgrade -y # buildkit
49.1 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV DEBIAN_FRONTEND=noninteractive
32 bytes
Digest: sha256:cf10bea649ffd16a8f20b8bf7133d1b3b5e113f7d3b9652523011f437c66894f
Command: RUN /bin/sh -c apt-get update && apt-get install --no-install-recommends -y ca-certificates curl iptables iproute2 iputils-ping knot-dnsutils netcat-openbsd tcpdump conntrack bsdmainutils net-tools lsof sudo && update-ca-certificates && apt-get upgrade -y && apt-get clean && rm -rf /var/log/*log /var/lib/apt/lists/* /var/log/apt/* /var/lib/dpkg/*-old /var/cache/debconf/*-old && update-alternatives --set iptables /usr/sbin/iptables-legacy && update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy # buildkit
10.0 MB
Digest: sha256:3eddda9fe510a9d71a57fcf2ff230cf59f121c2d30c18a4b143ce376ae22b5f7
Command: RUN /bin/sh -c useradd -m --uid 1337 istio-proxy && echo "istio-proxy ALL=NOPASSWD: ALL" >> /etc/sudoers # buildkit
4.8 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:26def7dccab085548ae76fd91ed812a36986168f226cca7e5cc4f585d607c81a
Command: COPY arm64/pilot-discovery /usr/local/bin/pilot-discovery # buildkit
28.4 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER 1337:1337
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/pilot-discovery"]
32 bytes
Docker logo
pilot
image arm64 linux
31.3 MB 1 week ago
2 tetrate-ci
Docker logo
pilot
image arm64 linux
112.1 MB 1 week ago
1 tetrate-ci
Docker logo
pilot
image amd64 linux
115.6 MB 1 week ago
1 tetrate-ci
Docker logo
pilot
image amd64 linux
76.4 MB 1 month ago
1 tetrate-ci
Docker logo
pilot
image arm64 linux
71.0 MB 1 month ago
1 tetrate-ci
Docker logo
pilot
image arm64 linux
33.0 MB 1 month ago
1 tetrate-ci
Docker logo
pilot
image amd64 linux
123.4 MB 1 month ago
52 tetrate-ci
Docker logo
pilot
image arm64 linux
121.9 MB 1 month ago
24 tetrate-ci
Docker logo
pilot
image amd64 linux
35.9 MB 1 month ago
1 tetrate-ci
Docker logo
pilot
image arm64 linux
76.1 MB 1 month ago
24 tetrate-ci
Docker logo
pilot
image arm64 linux
0 tetrate-ci
Docker logo
pilot
image amd64 linux
1 tetrate-ci
Docker logo
pilot
image amd64 linux
5 tetrate-ci
Docker logo
pilot
image arm64 linux
1 tetrate-ci
Docker logo
pilot
image arm64 linux
1 tetrate-ci
Docker logo
pilot
image amd64 linux
10 tetrate-ci
Docker logo
pilot
image arm64 linux
10 tetrate-ci
Docker logo
pilot
image amd64 linux
35.9 MB 1 week ago
1 tetrate-ci
Docker logo
pilot
image arm64 linux
112.9 MB 1 week ago
7 tetrate-ci
Docker logo
pilot
image amd64 linux
35.0 MB 1 week ago
1 tetrate-ci

Last scanned

3 months, 2 weeks ago

Scan result

Vulnerable

Vulnerability count

13

Max. severity

Medium
Target: ErdSbZFByeRm.sbom-cyclonedx.json (ubuntu 24.04)
MEDIUM

CVE-2026-22185: OpenLDAP: OpenLDAP LMDB: Denial of Service and Information Disclosure via Heap Buffer Underflow

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

Package Name: liblmdb0
Installed Version: 0.9.31-1build1
Fixed Version:

References: access.redhat.com bugs.openldap.org nvd.nist.gov seclists.org seclists.org www.cve.org www.openldap.org www.vulncheck.com
MEDIUM

CVE-2026-31790: openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.

Package Name: libssl3t64
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org www.openwall.com
MEDIUM

CVE-2026-31790: openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.

Package Name: openssl
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org www.openwall.com
MEDIUM

CVE-2025-45582: tar: Tar path traversal

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which "tar xf" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each "tar xf" in its Security Rules of Thumb; however, third-party advice leads users to run "tar xf" more than once into the same directory.

Package Name: tar
Installed Version: 1.35+dfsg-3build1
Fixed Version:

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com lists.gnu.org nvd.nist.gov www.cve.org www.gnu.org www.gnu.org www.gnu.org www.gnu.org
LOW

CVE-2025-29481: libbpf: Heap Buffer Overflow in libbpf

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

Package Name: libbpf1
Installed Version: 1:1.3.0-2build2
Fixed Version:

References: access.redhat.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2025-1352: elfutils: GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2025-1376: elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2024-2236: libgcrypt: vulnerable to Marvin Attack

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Package Name: libgcrypt20
Installed Version: 1.10.3-2build1
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org dev.gnupg.org errata.almalinux.org errata.rockylinux.org github.com gitlab.com linux.oracle.com linux.oracle.com lists.gnupg.org nvd.nist.gov www.cve.org
LOW

CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TL ...

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.

Package Name: libssl3t64
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-28388: Issue summary: When a delta CRL that contains a Delta CRL Indicator ex ...

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: libssl3t64
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-28389: Issue summary: During processing of a crafted CMS EnvelopedData messag ...

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: libssl3t64
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-28390: openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: libssl3t64
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-31789: Issue summary: Converting an excessively large OCTET STRING value to a ...

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: libssl3t64
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: login
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2026-28387: Issue summary: An uncommon configuration of clients performing DANE TL ...

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.

Package Name: openssl
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-28388: Issue summary: When a delta CRL that contains a Delta CRL Indicator ex ...

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: openssl
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-28389: Issue summary: During processing of a crafted CMS EnvelopedData messag ...

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: openssl
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-28390: openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: openssl
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-31789: Issue summary: Converting an excessively large OCTET STRING value to a ...

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Package Name: openssl
Installed Version: 3.0.13-0ubuntu3.7
Fixed Version: 3.0.13-0ubuntu3.9

References: github.com github.com github.com github.com github.com openssl-library.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: passwd
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull pilot @ reference/tag sha256:71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef:

docker pull containers.istio.tetratelabs.com/pilot@sha256:71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/pilot:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/pilot@sha256:71b0253b82e20ce00bb6ba679c6b3ca5d7d65f70535db4902a1b8725bd6f32ef
Top