openSUSE-SU-2026:21249-1: important: Security update for trivy
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for trivy
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21249-1
Rating: important
References:
* bsc#1269269
* bsc#1269271
Cross-References:
* CVE-2026-54448
* CVE-2026-55092
CVSS scores:
* CVE-2026-54448 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-54448 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55092 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-55092 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
Description:
This update for trivy fixes the following issues
Update to version 0.72.0.
- CVE-2026-54448: tar unpacker reads scanned Helm chart archives (.tgz) with `io.ReadAll(tr)` and defines no size
limit, which can lead to a DoS (bsc#1269271).
- CVE-2026-55092: `org.opencontainers.image.title` annotation from OCI artifact manifest is used as a destination
filename without validation and can lead to arbitrary file writes (bsc#1269269).
Other updates and bugfixes:
- Version 0.72.0:
* feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893)
* fix(misconf): support github_repository_vulnerability_alerts resource (#10680)
* feat(java): detect JAR licenses from packaged LICENSE files (#10856)
* fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861)
* fix(server): propagate package repository class in client/server mode (#10874)
* chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888)
* fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795)
* feat(java): detect JAR licenses from the embedded pom.xml (#10851)
* chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)
* ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873)
* chore(deps): bump alpine to 3.24.1 (#10868)
* docs: fix article typo in plugin developer guide (#10860)
* feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848)
* docs: fix typos (#10857)
* fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843)
* feat(secret): support new stateless format for GitHub App installation tokens (#10826)
* fix: correct format verbs in diagnostic messages (#10805)
* ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845)
* refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830)
* docs: fix repository scan heading typo (#10828)
* fix: forward ospkg detector options through ospkg.NewScanner (#10811)
* chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)
* fix(vex): load VEX documents from within the repository directory (#10820)
* ci!: migrate docker config to dockers_v2 (#10783)
* feat(dotnet): detect bundled runtime in self-contained deployments (#10786)
* feat(secret): add OpenAI secret detection rules (#10798)
* ci: expect GitHub App bot as backport PR author (#10813)
* fix: surface the original analysis error instead of context cancellation (#10793)
* chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803)
* chore(deps): bump the common group with 4 updates (#10797)
* chore(deps): bump the aws group with 4 updates (#10796)
* fix: use random suffix for process temp directory instead of PID (#10431)
* docs: update signature verification for deb and rpm packages (#10784)
* fix(image): lookup origin layer for custom resources in merged layers (#10788)
* ci: bump GoReleaser to v2.16.0 (#10774)
* docs: fix broken nixpkgs reference link in installation guide (#10776)
* fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777)
* fix(spdx): guard against nil root component in SPDX marshaler (#10771)
* ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1170=1
Package List:
- openSUSE Leap 16.0:
trivy-0.72.0-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-54448.html
* https://www.suse.com/security/cve/CVE-2026-55092.html