openSUSE-SU-2026:21835-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21835-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21835-1
Upstream
CVE (4)
Related
Published
2026-09-14T13:06:15Z
Modified
2026-09-15T18:23:34Z
Summary
Security update for trivy
Details

This update for trivy fixes the following issues:

  • CVE-2026-53495: containerd: CRI ExecSync goroutine leak can lead to node-level denial of service (bsc#1280111).
  • CVE-2026-56854: golang.org/x/crypto/ssh: unenforced source-address restrictions across non-public-key authentication callbacks can cause authorization bypasses and unauthorized client logins (bsc#1278624).
  • CVE-2026-56855: golang.org/x/crypto/ssh: unhandled RFC 4254 channel messages can cause connection deadlocks and denial of service (bsc#1278624).
  • CVE-2026-78662: golang.org/x/crypto/ssh: unvalidated incoming requests on unestablished channels can cause connection deadlocks and denial of service (bsc#1278624).
References

Affected packages

openSUSE:Leap 16.0 / trivy

Package

Name
trivy
Purl
pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.74.0-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "trivy":  "0.74.0-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21835-1.json"