[security][CVE-2026-76642] util-linux in Bun and Redis runtime images #168
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
"## Finding\n\n- CVE:
CVE-2026-76642\n- Component: util-linux family (bsdutils,libmount1, and related packages)\n- In-repo runtime versions:oven/bun:1.3.11(Debian 13.4, util-linux2.41-5) andredis:7.2(Debian 12.15, util-linux2.38.1-5+deb12u3)\n- Severity: High, Red Hat CVSS 3.17.8\n\n## Project impact\n\nA local attacker with a foothold in a container may use a failed external mount helper to run privileged post-mount hooks.\n\n## Remediation\n\nMove both base images to tags or digests that include the util-linux fix, then rescan the exact pulled digests. Avoid granting mount or privileged container capabilities until then.\n\n## Sources\n\n- https://nvd.nist.gov/vuln/detail/CVE-2026-76642\n- https://www.cve.org/CVERecord?id=CVE-2026-76642\n\n## Current automation counters\n\n- unaddressed critical CVEs: 2\n- unaddressed medium/low CVEs: 86\n- unaddressed total CVEs: 102\n"