Vulnerability Reportalmalinux:9.7-minimal-20260509

almalinux:9.7-minimal-20260509
digestsha256:ad7be7890c8841d62eae880cd43519bc273dc7165f05f5fd73b8db8a04272a7b

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
TRUSTED

This base/runtime image is a reasonable foundation, but it ships vulnerabilities worth remediating in the images built on top of it. While 58 exposed vulnerabilities are present, the maximum severity is 6.29 and the most notable ones are CVE-2026-42011 (certificate validation bypass in gnutls) and CVE-2026-54369 (local symlink traversal in libacl). These could allow spoofing or local privilege escalation if the final image handles untrusted certificates or runs privileged operations, so they should be patched before production deployment. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

67 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42011MEDIUM6.29
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42012MEDIUM6.03
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-54369MEDIUM6.03
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap
2.48-10.el9_7.1
fixed in 2.48-10.el9_8.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.16.0-9.el9
fixed in 4.16.0-10.el9_8
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-2.el9_8
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42010MEDIUM5.88
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-42014MEDIUM5.61
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14512MEDIUM5.52
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-common
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.9.13-14.el9_7
fixed in 2.9.13-14.el9_8.1
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-4.el9
fixed in 2.4.0-1.el9_8
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-14087MEDIUM5
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-45447MEDIUM4.86
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
5.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33845MEDIUM4.64
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM4.5
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-42009MEDIUM4.5
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-3.el9_8
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.34-231.el9_7.10
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.34-231.el9_7.10
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-272.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-274.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM4.18
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-40355LOW3.83
krb5-libs
1.21.1-9.el9_7
fixed in 1.21.1-10.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-40356LOW3.83
krb5-libs
1.21.1-9.el9_7
fixed in 1.21.1-10.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34182LOW3.77
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-3832LOW3.15
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-58016LOW2.78
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit-trust
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42013LOW2.51
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.24-3.el9
fixed in 0.7.24-6.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-29111LOW2.39
systemd-libs
252-55.el9_7.9.alma.1
fixed in 252-67.el9_8.2.alma.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-3833LOW2.26
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-39.el9
fixed in 8.32-41.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-6170LOW2.12
libxml2
2.9.13-14.el9_7
fixed in 2.9.13-14.el9_8.2
0.2%
Theoretical Threat
Directly Exposed

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.