Index › shell › bsdextrautils bsdextrautils 8 tools · 1 release line The 4.4BSD text filters from util-linux: col, colrm, column, hexdump, look, rev and ul. Each tool carries its own sandbox boundary — they are not the same. $ kapsl col ⧉ $ kapsl colrm ⧉ $ kapsl column ⧉ $ kapsl hd ⧉ $ kapsl hexdump ⧉ $ kapsl look ⧉ $ kapsl rev ⧉ $ kapsl ul ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 2.41.3 stable 2026-08-30 7 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect capabilities differ between them Tool Capabilities Seccomp Findings Image Description ▸ col nomount default M7 bsdextrautils Filter reverse line feeds out of standard input ▸ colrm nomount default M7 bsdextrautils Remove a range of columns from standard input ▸ column ro default M7 bsdextrautils Format input into columns or an aligned table ▸ hd ro default M7 bsdextrautils Canonical hex and ASCII dump of file contents ▸ hexdump ro default M7 bsdextrautils Display file contents in hexadecimal, decimal, octal or ASCII ▸ look ro default M7 bsdextrautils Display lines beginning with a given string ▸ rev ro default M7 bsdextrautils Reverse the characters of every line ▸ ul ro default M7 bsdextrautils Convert underscore overstriking to terminal underlining ▸ showing col colrm column hd hexdump look rev ul from bsdextrautils@latest → 2.41.3 stable Findings M7 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. CVE-2026-53612 ↗ M — util-linux CVE-2026-53612 CVE-2026-53613 ↗ M — util-linux CVE-2026-53613 CVE-2026-53614 ↗ M — util-linux CVE-2026-53614 CVE-2026-53615 ↗ M — util-linux CVE-2026-53615 These are the findings of bsdextrautils, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image repository ghcr.io/kapsl-sh/bsdextrautils platforms amd64 sha256:746f…0d03 copy arm64 sha256:b962…1636 copy size <1 MB unpacked · 1 layer base scratch signed cosign · 2026-08-30 · public key last scan 2026-08-30 Sandbox boundary col capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary colrm capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary column capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary hd capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary hexdump capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary look capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded WORDLIST Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary rev capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary ul capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-30 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 7 findings across this project at latest. Counted once per advisory across every image the project builds.