Cryptopsyby CloudTrace

Image reports › ubuntu

ubuntu — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/ubuntu · Ubuntu 26.04.1 LTS

Latest: ubuntu:latest · checked 2026-09-25

Not FIPS-ready

No. ubuntu:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 93 known vulnerabilities

93 known vulnerabilities in 22 packages (47 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
highUBUNTU-CVE-2026-86145libpcre2-8-0 10.46-1build1no fix yetPCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regul
highUBUNTU-CVE-2026-78408bsdutils 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libblkid1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libmount1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libsmartcols1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408libuuid1 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408login 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408mount 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-78408util-linux 2.41.3-3ubuntu2.2no fix yetThe nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an atta
highUBUNTU-CVE-2026-76642bsdutils 2.41.3-3ubuntu2.2no fix yetutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit
highUBUNTU-CVE-2026-78410bsdutils 2.41.3-3ubuntu2.2no fix yetA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta
highUBUNTU-CVE-2026-76642libblkid1 2.41.3-3ubuntu2.2no fix yetutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit
highUBUNTU-CVE-2026-78410libblkid1 2.41.3-3ubuntu2.2no fix yetA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta
highUBUNTU-CVE-2026-76642libmount1 2.41.3-3ubuntu2.2no fix yetutil-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherit
highUBUNTU-CVE-2026-78410libmount1 2.41.3-3ubuntu2.2no fix yetA flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fsta

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyC 932026-09-25Full report