Image reports › ubuntu
ubuntu — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/ubuntu · Ubuntu 26.04.1 LTS
Latest: ubuntu:latest · checked 2026-09-25
Not FIPS-ready
No. ubuntu:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 93 known vulnerabilities
93 known vulnerabilities in 22 packages (47 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | UBUNTU-CVE-2026-86145 | libpcre2-8-0 10.46-1build1 | no fix yet | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regul |
| high | UBUNTU-CVE-2026-78408 | bsdutils 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | libblkid1 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | libmount1 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | libsmartcols1 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | libuuid1 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | login 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | mount 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-78408 | util-linux 2.41.3-3ubuntu2.2 | no fix yet | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta |
| high | UBUNTU-CVE-2026-76642 | bsdutils 2.41.3-3ubuntu2.2 | no fix yet | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit |
| high | UBUNTU-CVE-2026-78410 | bsdutils 2.41.3-3ubuntu2.2 | no fix yet | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta |
| high | UBUNTU-CVE-2026-76642 | libblkid1 2.41.3-3ubuntu2.2 | no fix yet | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit |
| high | UBUNTU-CVE-2026-78410 | libblkid1 2.41.3-3ubuntu2.2 | no fix yet | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta |
| high | UBUNTU-CVE-2026-76642 | libmount1 2.41.3-3ubuntu2.2 | no fix yet | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit |
| high | UBUNTU-CVE-2026-78410 | libmount1 2.41.3-3ubuntu2.2 | no fix yet | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | C 93 | 2026-09-25 | Full report |