Index › system › util-linux util-linux 14 tools · 1 release line Core Linux system utilities: the more pager, getopt, flock, and file, process and CPU helpers. Each tool carries its own sandbox boundary — they are not the same. $ kapsl more ⧉ $ kapsl getopt ⧉ $ kapsl namei ⧉ $ kapsl flock ⧉ $ kapsl fallocate ⧉ $ kapsl hardlink ⧉ $ kapsl mcookie ⧉ $ kapsl rename.ul ⧉ $ kapsl exch ⧉ $ kapsl taskset ⧉ $ kapsl prlimit ⧉ $ kapsl chrt ⧉ $ kapsl ionice ⧉ $ kapsl lscpu ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 2.41.3 stable 2026-08-30 7 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect capabilities differ between them Tool Capabilities Seccomp Findings Image Description ▸ more ro default M7 util-linux Page through text one screenful at a time ▸ getopt nomount default M7 util-linux Parse command options for shell scripts ▸ namei ro default M7 util-linux Follow a pathname until a terminal point is found ▸ flock rw default M7 util-linux Run a command under a file lock ▸ fallocate rw default M7 util-linux Preallocate or deallocate space in a file ▸ hardlink rw default M7 util-linux Replace identical files with hard links ▸ mcookie ro default M7 util-linux Generate a random 128-bit hexadecimal cookie ▸ rename.ul rw default M7 util-linux Rename files by substituting one string for another ▸ exch rw default M7 util-linux Atomically exchange the paths of two files ▸ taskset rw default M7 util-linux Run a command on a chosen set of CPUs ▸ prlimit rw default M7 util-linux Show or set a process's resource limits ▸ chrt rw default M7 util-linux Run a command with a chosen scheduling policy and priority ▸ ionice rw default M7 util-linux Run a command with a chosen I/O scheduling class ▸ lscpu nomount default M7 util-linux Display information about the CPU architecture ▸ showing more getopt namei flock fallocate hardlink mcookie rename.ul exch taskset prlimit chrt ionice lscpu from util-linux@latest → 2.41.3 stable Findings M7 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. CVE-2026-53612 ↗ M — util-linux CVE-2026-53612 CVE-2026-53613 ↗ M — util-linux CVE-2026-53613 CVE-2026-53614 ↗ M — util-linux CVE-2026-53614 CVE-2026-53615 ↗ M — util-linux CVE-2026-53615 These are the findings of util-linux, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default + bash runtime none — self-contained composes bash Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image repository ghcr.io/kapsl-sh/util-linux platforms amd64 sha256:50b7…6763 copy arm64 sha256:a4f7…0ff3 copy size 2 MB unpacked · 1 layer base scratch signed cosign · 2026-08-30 · public key last scan 2026-08-30 Sandbox boundary more capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded MORE Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary getopt capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded GETOPT_COMPATIBLE Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary namei capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary flock capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary fallocate capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary hardlink capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary mcookie capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary rename.ul capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary exch capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary taskset capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary prlimit capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary chrt capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary ionice capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary lscpu capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-30 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 7 findings across this project at latest. Counted once per advisory across every image the project builds.