CVE-2022-22704
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the c…
All CVEs associated with "Alpine Linux". Page 1/1 • 9 CVEs.
A curated feed of “Alpine Linux”-related CVEs appears below. We currently track 9 CVEs for this tag (all time). In the last 365 days, 0 were published. Average CVSS is 7.7 (all time), and 67% are rated High/Critical (all time). Top CWEs (all time): CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer, CWE-909 - Missing Initialization of Resource, CWE-312 - Cleartext Storage of Sensitive Information.
In our taxonomy this topic maps to a MODERATE impact class. Issues here typically affect operating system packages or kernels. Plan reboots or service restarts and coordinate rollouts across fleets. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | EOL | LTS |
|---|---|---|---|---|
| 3.23 | 3.23.4 | |||
| 3.22 | 3.22.4 | |||
| 3.21 | 3.21.7 | Soon | ||
| 3.20 | 3.20.10 | Expired | ||
| 3.19 | 3.19.9 | Expired | ||
| 3.18 | 3.18.12 | Expired | ||
| 3.17 | 3.17.10 | Expired | ||
| 3.16 | 3.16.9 | Expired | ||
| 3.15 | 3.15.11 | Expired | ||
| 3.14 | 3.14.10 | Expired | ||
| 3.13 | 3.13.12 | Expired | ||
| 3.12 | 3.12.12 | Expired | ||
| 3.11 | 3.11.13 | Expired | ||
| 3.10 | 3.10.9 | Expired | ||
| 3.9 | 3.9.6 | Expired | ||
| 3.8 | 3.8.5 | Expired | ||
| 3.7 | 3.7.3 | Expired | ||
| 3.6 | 3.6.5 | Expired | ||
| 3.5 | 3.5.3 | Expired | ||
| 3.4 | 3.4.6 | Expired | ||
| 3.3 | 3.3.3 | Expired | ||
| 3.2 | 3.2.3 | Expired | ||
| 3.1 | 3.1.4 | Expired | ||
| 3.0 | 3.0.6 | Expired | ||
| 2.7 | 2.7.9 | Expired | ||
| 2.6 | 2.6.8 | Expired | ||
| 2.5 | 2.5.4 | Expired | ||
| 2.4 | 2.4.11 | Expired | ||
| 2.3 | 2.3.6 | Expired | ||
| 2.2 | 2.2.5 | Expired | ||
| 2.1 | 2.1.6 | Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Alpine Linux” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the c…
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 201…
Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This att…
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax h…
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file.