Image reports › ocimend.io/ubuntu
ocimend.io/ubuntu — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/ubuntu · Ubuntu 24.04.4 LTS
Latest: ocimend.io/ubuntu:noble-20260210.1-fips · checked 2026-09-26
Not FIPS-ready
No. ubuntu:noble-20260210.1-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 6 known vulnerabilities
6 known vulnerabilities in 6 packages (2 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in noble-20260210.1-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | UBUNTU-CVE-2016-20013 | libc-bin 2.39-0ubuntu8.7 | no fix yet | sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password. |
| high | UBUNTU-CVE-2016-20013 | libc6 2.39-0ubuntu8.7 | no fix yet | sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| noble-20260210.1-fips | Not FIPS-ready | A 6 | 2026-09-26 | Full report |