kapsl Index
Docs Releases

gcc

4 tools · 1 release line

The GNU C and C++ compilers. Every tool here carries the same sandbox boundary.

kapsl gcc
kapsl cc
kapsl g++
kapsl c++

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing gcc cc g++ c++ from gcc@latest → 15.2.0 stable

Findings

M1L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-6791 ↗ M 6.6 glibc When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.
CVE-2026-6368 ↗ L 2.1 glibc Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of gcc-cc, which ships gcc, cc. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding.

Findings

M2L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-6791 ↗ M 6.6 glibc When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVE-2026-6368 ↗ L 2.1 glibc Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

These are the findings of gcc-cxx, which ships g++, c++. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime binutils
composes binutils

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime binutils
composes binutils

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime binutils
composes binutils

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime binutils
composes binutils

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/gcc-cc:15.2.0
digest
platforms
size 68 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/gcc-cxx:15.2.0
digest
platforms
size 121 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

gcc

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

1 forwarded

GCC_COLORS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

4 set

COMPILER_PATHC_INCLUDE_PATHGCC_EXEC_PREFIXLD_LIBRARY_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Sandbox boundary

cc

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

1 forwarded

GCC_COLORS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

4 set

COMPILER_PATHC_INCLUDE_PATHGCC_EXEC_PREFIXLD_LIBRARY_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Sandbox boundary

g++

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

1 forwarded

GCC_COLORS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

5 set

COMPILER_PATHCPLUS_INCLUDE_PATHC_INCLUDE_PATHGCC_EXEC_PREFIXLD_LIBRARY_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Sandbox boundary

c++

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

1 forwarded

GCC_COLORS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

5 set

COMPILER_PATHCPLUS_INCLUDE_PATHC_INCLUDE_PATHGCC_EXEC_PREFIXLD_LIBRARY_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

3 findings across this project at latest. Counted once per advisory across every image the project builds.