openSUSE-SU-2026:21072-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21072-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21072-1
Upstream
CVE (7)
Related
Published
2026-06-26T09:25:10Z
Modified
2026-06-30T18:24:45Z
Summary
Security update for trivy
Details

This update for trivy fixes the following issues

Update to version 0.71.2:

  • CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267268).
  • CVE-2026-46680: github.com/containerd/containerd/v2/pkg/oci: containerd user ID handling bypass allows runAsNonRoot evasion (bsc#1268356).
  • CVE-2026-47262: github.com/containerd/containerd/v2/pkg/oci: Denial of Service (DoS) condition via a maliciously crafted image (bsc#1268440).
  • CVE-2026-50195: containerd: fails to validate the image references specified within a checkpoint image's configuration (bsc#1268399).
  • CVE-2026-53488: containerd: CRI plugin propagates labels from an image config to a container without validation (bsc#1268400).
  • CVE-2026-53489: containerd: CRI plugin restores container.log from a checkpoint image without validating a symlinked path (bsc#1268404).
  • CVE-2026-53492: containerd: improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration (bsc#1268403).

Changes for trivy:

  • release: v0.71.2 [release/v0.71] (#10871)
  • fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)
  • chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)
  • fix(oci): validate artifact filename
  • fix: forward ospkg detector options through ospkg.NewScanner
  • fix(vex): load VEX documents from within the repository directory
  • fix: surface the original analysis error instead of context cancellation
  • ci: expect GitHub App bot as backport PR author
References

Affected packages

openSUSE:Leap 16.0 / trivy

Package

Name
trivy
Purl
pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.71.2-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "trivy":  "0.71.2-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21072-1.json"