ISOMAN

Filtered CVEs

Alpine Linux CVEs

CVEs linked to tracked Alpine Linux releases.

Release Context

  1. Alpine Linux · 3.24.0 x86_64 extended
  2. Alpine Linux · 3.24.0 x86_64 standard
  3. Alpine Linux · 3.24.0 x86_64 virt
  4. Alpine Linux · 3.24.0 x86_64 xen
  5. Alpine Linux · 3.24.0 x86 extended
  6. Alpine Linux · 3.24.0 x86 standard
  7. Alpine Linux · 3.24.0 x86 virt
  8. Alpine Linux · 3.24.0 aarch64 rpi
  9. Alpine Linux · 3.24.0 aarch64 standard
  10. Alpine Linux · 3.24.0 aarch64 virt
  11. Alpine Linux · 3.24.0 armhf rpi
  12. Alpine Linux · 3.24.0 armv7 rpi
  13. Alpine Linux · 3.24.0 armv7 standard
  14. Alpine Linux · 3.24.0 armv7 virt
  15. Alpine Linux · 3.24.0 loongarch64 standard
  16. Alpine Linux · 3.24.0 ppc64le standard
  17. Alpine Linux · 3.24.0 riscv64 standard
  18. Alpine Linux · 3.24.0 s390x standard
  19. Alpine Linux · 3.24.1 x86_64 extended
  20. Alpine Linux · 3.24.1 x86_64 standard
  21. Alpine Linux · 3.24.1 x86_64 virt
  22. Alpine Linux · 3.24.1 x86_64 xen
  23. Alpine Linux · 3.24.1 x86 extended
  24. Alpine Linux · 3.24.1 x86 standard
  25. Alpine Linux · 3.24.1 x86 virt
  26. Alpine Linux · 3.24.1 aarch64 rpi
  27. Alpine Linux · 3.24.1 aarch64 standard
  28. Alpine Linux · 3.24.1 aarch64 virt
  29. Alpine Linux · 3.24.1 armhf rpi
  30. Alpine Linux · 3.24.1 armv7 rpi
  31. Alpine Linux · 3.24.1 armv7 standard
  32. Alpine Linux · 3.24.1 armv7 virt
  33. Alpine Linux · 3.24.1 loongarch64 standard
  34. Alpine Linux · 3.24.1 ppc64le standard
  35. Alpine Linux · 3.24.1 riscv64 standard
  36. Alpine Linux · 3.24.1 s390x standard

5 CVEs

  1. CVE-2022-22704
    CRITICAL · CVSS 9.8 ·

    The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

  2. CVE-2019-5021
    CRITICAL · CVSS 9.8 ·

    Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

  3. CVE-2018-1000849
    HIGH · CVSS 8.8 ·

    Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file, due to bugs in handling long link target name and the way a regular file is extracted.. This vulnerability appears to have been fixed in 2.6.10, 2.7.6, and 2.10.1.

  4. CVE-2017-9671
    HIGH · CVSS 7.8 ·

    A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block.

  5. CVE-2017-9669
    HIGH · CVSS 7.8 ·

    A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file.