Ocimendby CloudTrace

Image reports › ocimend.io/ubuntu

ocimend.io/ubuntu — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/ubuntu · Ubuntu 24.04.4 LTS

Latest: ocimend.io/ubuntu:noble-20260210.1-fips · checked 2026-09-26

Not FIPS-ready

No. ubuntu:noble-20260210.1-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade A: 6 known vulnerabilities

6 known vulnerabilities in 6 packages (2 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in noble-20260210.1-fips

SeverityIDPackageFixed inSummary
highUBUNTU-CVE-2016-20013libc-bin 2.39-0ubuntu8.7no fix yetsha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
highUBUNTU-CVE-2016-20013libc6 2.39-0ubuntu8.7no fix yetsha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
noble-20260210.1-fipsNot FIPS-readyA 62026-09-26Full report