kapsl Index
Docs Releases

r-project

2 tools · 1 release line

R language and environment for statistical computing and graphics. Each tool carries its own sandbox boundary — they are not the same.

kapsl R
kapsl Rscript

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

capabilities differ between them

Tool Capabilities Seccomp Findings Image Description
showing R Rscript from r-project@latest → 4.6.1 stable

Findings

H6M2L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-66032 ↗ H 8.7 libssh2 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session.
CVE-2026-66033 ↗ H 8.7 libssh2 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by…
CVE-2026-66034 ↗ H 7.7 libssh2 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the…
CVE-2026-66035 ↗ H 7.7 libssh2 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length…
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-8932 ↗ H 7.5 curl libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.
CVE-2026-13757 ↗ M 6.2 p11-kit A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing…
CVE-2026-18938 ↗ M 6.2 p11-kit A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability.
CVE-2026-75803 ↗ L openssl CVE-2026-75803

2 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex

These are the findings of r-project, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + sed, tar, gzip, grep, make, g++, gcc
runtime bash, coreutils, which
composes bash, coreutils, which, sed, tar, gzip, grep, make, g++, gcc

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + sed, tar, gzip, grep, make, g++, gcc
runtime bash, coreutils, which
composes bash, coreutils, which, sed, tar, gzip, grep, make, g++, gcc

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/r-project:4.6.1
digest
platforms
size 73 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

R

capabilities

nomountrw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.Rprofile
  • ~/.Renviron
  • ~/.R
  • ~/R · writable

env passed through

12 forwarded

EDITORR_DEFAULT_PACKAGESR_ENVIRON_USERR_HISTFILER_HISTSIZER_LIBSR_LIBS_SITER_LIBS_USERR_PAPERSIZER_PROFILE_USERTMPDIRVISUAL

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

7 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPAGERPKG_CONFIG_PATHR_GZIPCMDTAR

per-subcommand

grants differ

RHOME + nomount rw

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Sandbox boundary

Rscript

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.Rprofile
  • ~/.Renviron
  • ~/.R
  • ~/R · writable

env passed through

14 forwarded

EDITORR_DEFAULT_PACKAGESR_ENVIRON_USERR_HISTFILER_HISTSIZER_LIBSR_LIBS_SITER_LIBS_USERR_PAPERSIZER_PROFILE_USERR_SCRIPT_DEFAULT_PACKAGESR_SCRIPT_LEGACYTMPDIRVISUAL

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

7 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPAGERPKG_CONFIG_PATHR_GZIPCMDTAR

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

9 findings across this project at latest. Counted once per advisory across every image the project builds.