Cryptopsyby CloudTrace

Image reports › eclipse-temurin

eclipse-temurin — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/eclipse-temurin · Ubuntu 26.04.1 LTS

Latest: eclipse-temurin:latest · checked 2026-09-25

Not FIPS-ready

No. eclipse-temurin:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 340 known vulnerabilities

340 known vulnerabilities in 35 packages (82 high); 2 can be fixed by upgrading 1 package. Start with libexpat1: upgrade 2.7.4-1 → 2.7.4-1ubuntu0.2 (fixes 2).

Open the full interactive report → Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
libexpat12.7.4-12.7.4-1ubuntu0.22

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
highUBUNTU-CVE-2026-86145libpcre2-8-0 10.46-1build1no fix yetPCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regul
highUBUNTU-CVE-2026-78408bsdutils 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libblkid1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libmount1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libsmartcols1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libuuid1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408login 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408mount 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408util-linux 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUSN-8813-1libexpat1 2.7.4-12.7.4-1ubuntu0.2expat vulnerabilities
highUBUNTU-CVE-2026-6846binutils 2.46-3ubuntu2no fix yetA flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution,
highUBUNTU-CVE-2026-6846binutils-common 2.46-3ubuntu2no fix yetA flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution,
highUBUNTU-CVE-2026-6846binutils-x86-64-linux-gnu 2.46-3ubuntu2no fix yetA flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution,
highUBUNTU-CVE-2026-76642bsdutils 2.41.3-3ubuntu2.2no fix yetutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit
highUBUNTU-CVE-2026-78410bsdutils 2.41.3-3ubuntu2.2no fix yetA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyC 3402026-09-25Full report