Vulnerability Reportmanticoresearch/manticore:dev-27.0.0

manticoresearch/manticore:dev-27.0.0-801beeamanticoresearch/manticore:dev-27.0.0
DIGESTsha256:7cc166404db3eeffe2c4f899b0acbce70ba85ace62613e97279eddda58229b1b

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The image has 69 known vulnerabilities on its exposed surface, with two medium-severity CVEs: CVE-2026-41989 (remote denial of service via crafted ECDH ciphertext during TLS handshake) and CVE-2026-42010 (authentication bypass if RSA-PSK is enabled, which is non-default). Post-exploit findings are all low severity, so the main risk is availability. Disabling RSA-PSK or ECDHE ciphersuites would fully mitigate the respective vulnerabilities.

Vulnerabilities

Vulnerability Log

120 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42010MEDIUM6.66
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-41989MEDIUM6.38
libgcrypt20
1.10.3-2build1
fixed in 1.10.3-2ubuntu0.1
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42014MEDIUM5.61
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42013MEDIUM5.58
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5260MEDIUM5.58
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2017-13716MEDIUM5.5
libbinutils
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2017-13716MEDIUM5.5
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2017-13716MEDIUM5.5
libctf0
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2017-13716MEDIUM5.5
libgprofng0
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2017-13716MEDIUM5.5
libsframe1
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2026-3833MEDIUM5.03
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42011MEDIUM5.03
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM4.82
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-2236MEDIUM4.72
libgcrypt20
1.10.3-2build1
No fix yet
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-69651MEDIUM4.67
libbinutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69651MEDIUM4.67
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69651MEDIUM4.67
libctf0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.6.1-2ubuntu0.4
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69651MEDIUM4.67
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69651MEDIUM4.67
libsframe1
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM4.42
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4437MEDIUM4.42
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-27456MEDIUM4
libblkid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libfdisk1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2017-13716LOW3.3
binutils
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2017-13716LOW3.3
binutils-common
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2017-13716LOW3.3
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2025-1152LOW3.15
libbinutils
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-1152LOW3.15
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-1152LOW3.15
libctf0
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3832LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-1152LOW3.15
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-1152LOW3.15
libsframe1
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-45582LOW2.86
tar
1.35+dfsg-3build1
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69651LOW2.8
binutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69651LOW2.8
binutils-common
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69651LOW2.8
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69647LOW2.8
libbinutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69648LOW2.8
libbinutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69652LOW2.8
libbinutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69647LOW2.8
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69648LOW2.8
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69652LOW2.8
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69647LOW2.8
libctf0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69648LOW2.8
libctf0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69652LOW2.8
libctf0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69647LOW2.8
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69648LOW2.8
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69652LOW2.8
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69647LOW2.8
libsframe1
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69648LOW2.8
libsframe1
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69652LOW2.8
libsframe1
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd-shared
255.4-1ubuntu8.16
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libsystemd0
255.4-1ubuntu8.16
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
255.4-1ubuntu8.16
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33845LOW2.78
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
bsdutils
1:2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.39.3-9ubuntu6.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-69644LOW2.38
libbinutils
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69645LOW2.38
libbinutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69646LOW2.38
libbinutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69644LOW2.38
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69645LOW2.38
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69646LOW2.38
libctf-nobfd0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69644LOW2.38
libctf0
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69645LOW2.38
libctf0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69646LOW2.38
libctf0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69644LOW2.38
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69645LOW2.38
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69646LOW2.38
libgprofng0
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69644LOW2.38
libsframe1
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69645LOW2.38
libsframe1
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69646LOW2.38
libsframe1
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33846LOW2.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-42009LOW2.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.8%
Theoretical Threat
Post-Exploit
CVE-2021-31879LOW2.2
wget
1.21.4-1ubuntu4.1
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
libc-bin
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6238LOW1.99
libc6
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-1152LOW1.89
binutils
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1152LOW1.89
binutils-common
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1152LOW1.89
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
login
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
passwd
1:4.13+dfsg1-4ubuntu3.2
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc-bin
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5435LOW1.81
libc6
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69647LOW1.68
binutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69648LOW1.68
binutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69652LOW1.68
binutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69647LOW1.68
binutils-common
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69648LOW1.68
binutils-common
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69652LOW1.68
binutils-common
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69647LOW1.68
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69648LOW1.68
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69652LOW1.68
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4046LOW1.62
libc-bin
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4046LOW1.62
libc6
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42015LOW1.62
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-69644LOW1.43
binutils
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-69645LOW1.43
binutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69646LOW1.43
binutils
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69644LOW1.43
binutils-common
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-69645LOW1.43
binutils-common
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69646LOW1.43
binutils-common
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69644LOW1.43
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-69645LOW1.43
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69646LOW1.43
binutils-x86-64-linux-gnu
2.42-4ubuntu2.10
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4437NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6238NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-5435NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-4046NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.4%
Theoretical Threat
Not Applicable
CVE-2026-4438NONE0
locales
2.39-0ubuntu8.7
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40228NONE0
systemd
255.4-1ubuntu8.16
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40228NONE0
systemd-dev
255.4-1ubuntu8.16
No fix yet
0.2%
Theoretical Threat
Not Applicable