openSUSE-SU-2026:0263-1: important: Security update for trivy

[email protected] Mon, 27 Jul 2026 12:05:09 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for trivy
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0263-1
Rating:             important
References:         #1266495 #1268356 #1269269 #1269271 #1271658 
                    #1271670 
Cross-References:   CVE-2026-39821 CVE-2026-46680 CVE-2026-50151
                    CVE-2026-54448 CVE-2026-55092 CVE-2026-56852
                   
CVSS scores:
                    CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
                    CVE-2026-46680 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
                    CVE-2026-50151 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
                    CVE-2026-54448 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
                    CVE-2026-55092 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
                    CVE-2026-56852 (SUSE): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 6 vulnerabilities is now available.

Description:

   This update for trivy fixes the following issues:

   - Update embedded dependencies:
     * update x/net to 0.57.0 (boo#1266495, CVE-2026-39821)
     * update x/text to 0.40.0 (boo#1271670, CVE-2026-56852)
     * update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151)

   - Update trivy to version 0.72.0:
     * release: v0.72.0 [main] (#10782)
     * test: close plugin manager in tests cleanup (#10904)
     * Merge commit from fork
     * feat(bottlerocket): add vulnerability matching for Bottlerocket OS
       (#10893)
     * fix(misconf): support github_repository_vulnerability_alerts resource
       (#10680)
     * feat(java): detect JAR licenses from packaged LICENSE files (#10856)
     * fix(nodejs): parse project dependencies from multi-document
       pnpm-lock.yaml (#10861)
     * fix(server): propagate package repository class in client/server mode
       (#10874)
     * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to
       2.3.2 (#10888)
     * fix(vuln): fall back to UNKNOWN severity when vulnerability details
       are missing (#10795)
     * feat(java): detect JAR licenses from the embedded pom.xml (#10851)
     * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)
     * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2
       (#10873)
     * chore(deps): bump alpine to 3.24.1 (#10868)
     * docs: fix article typo in plugin developer guide (#10860)
     * feat(misconf): Adds CloudFront standard logging v2 support to
       AVD-AWS-0010 (#10848)
     * docs: fix typos (#10857)
     * fix(terraform): avoid data race on global getter.Getters in remote
       module resolver (#10843)
     * feat(secret): support new stateless format for GitHub App installation
       tokens (#10826)
     * fix: correct format verbs in diagnostic messages (#10805)
     * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1
       (#10845)
     * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist
       (#10830)
     * docs: fix repository scan heading typo (#10828)
     * Merge commit from fork
     * fix: forward ospkg detector options through ospkg.NewScanner (#10811)
     * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)
     * fix(vex): load VEX documents from within the repository directory
       (#10820)
     * ci!: migrate docker config to dockers_v2 (#10783)
     * feat(dotnet): detect bundled runtime in self-contained deployments
       (#10786)
     * feat(secret): add OpenAI secret detection rules (#10798)
     * ci: expect GitHub App bot as backport PR author (#10813)
     * fix: surface the original analysis error instead of context
       cancellation (#10793)
     * chore(deps): bump the github-actions group across 1 directory with 11
       updates (#10803)
     * chore(deps): bump the common group with 4 updates (#10797)
     * chore(deps): bump the aws group with 4 updates (#10796)
     * fix: use random suffix for process temp directory instead of PID
       (#10431)
     * docs: update signature verification for deb and rpm packages (#10784)
     * fix(image): lookup origin layer for custom resources in merged layers
       (#10788)
     * test: fix flaky containerd integration test (#10760)
     * ci: bump GoReleaser to v2.16.0 (#10774)
     * docs: fix broken nixpkgs reference link in installation guide (#10776)
     * test(java): force offline-scan for client/server integration tests
       (#10721)
     * fix(image): deterministic OS package deduplication for images with
       embedded SBOMs (#10777)
     * fix(spdx): guard against nil root component in SPDX marshaler (#10771)
     * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0
       (#10768)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-263=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      trivy-0.72.0-bp157.2.15.1


References:

   https://www.suse.com/security/cve/CVE-2026-39821.html
   https://www.suse.com/security/cve/CVE-2026-46680.html
   https://www.suse.com/security/cve/CVE-2026-50151.html
   https://www.suse.com/security/cve/CVE-2026-54448.html
   https://www.suse.com/security/cve/CVE-2026-55092.html
   https://www.suse.com/security/cve/CVE-2026-56852.html
   https://bugzilla.suse.com/1266495
   https://bugzilla.suse.com/1268356
   https://bugzilla.suse.com/1269269
   https://bugzilla.suse.com/1269271
   https://bugzilla.suse.com/1271658
   https://bugzilla.suse.com/1271670