Vulnerability Reportalmalinux:9.7-minimal-20260407

almalinux:9.7-minimal-20260407
digestsha256:fb3377c233c7797b84cd18ccfc479fbb5fb8321d0e997bb12e10cd204ef5649b

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
TRUSTED

This base/runtime image carries significant vulnerabilities that any image built on it would inherit; remediate them in the final image before production. An attacker could leverage issues in libarchive and gnutls to read heap memory or bypass certificate name constraints, potentially leaking sensitive information or enabling spoofing. These are mostly medium-severity issues, and post-exploit findings are low-severity, so the image is a reasonable foundation but should be patched before deployment. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

70 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-4424MEDIUM6.38
libarchive
3.5.3-7.el9_7
fixed in 3.5.3-9.el9_7
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42012MEDIUM6.03
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54369MEDIUM6.03
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap
2.48-10.el9
fixed in 2.48-10.el9_8.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.16.0-9.el9
fixed in 4.16.0-10.el9_8
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-2.el9_8
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42014MEDIUM5.61
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14512MEDIUM5.52
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.9.13-14.el9_7
fixed in 2.9.13-14.el9_8.1
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-231.el9_7.10
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-231.el9_7.10
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42010LOW3.53
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-4438LOW3.4
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-3832LOW3.15
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14087LOW3
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.1
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33845LOW2.78
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33846LOW2.7
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-42009LOW2.7
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-5121LOW2.7
libarchive
3.5.3-7.el9_7
fixed in 3.5.3-9.el9_7
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-3.el9_8
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit-trust
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42013LOW2.51
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5260LOW2.51
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.24-3.el9
fixed in 0.7.24-6.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-29111LOW2.39
systemd-libs
252-55.el9_7.7.alma.1
fixed in 252-67.el9_8.2.alma.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40355LOW2.29
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-40356LOW2.29
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-27135LOW2.29
libnghttp2
1.43.0-6.el9
fixed in 1.43.0-6.el9_7.1
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-39.el9
fixed in 8.32-41.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-6170LOW2.12
libxml2
2.9.13-14.el9_7
fixed in 2.9.13-14.el9_8.2
0.2%
Theoretical Threat
Directly Exposed

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.