openSUSE-SU-2026:0312-1: moderate: Security update for trivy
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE Security Update: Security update for trivy
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0312-1
Rating: moderate
References: #1276128
Cross-References: CVE-2026-72815 CVE-2026-72816 CVE-2026-72817
CVSS scores:
CVE-2026-72815 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVE-2026-72816 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVE-2026-72817 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for trivy fixes the following issues:
- Update to version 0.74.0:
* release: v0.74.0 [main] (#11037)
* chore(deps): update golang.org/x modules (#11094)
* chore(deps): bump the docker group with 2 updates (#11090)
* docs: update release branch ruleset instructions (#11093)
* chore(deps): bump the common group across 1 directory with 7 updates
(#11086)
* fix(misconf): unmark cty values outside the evaluation context (#11078)
* chore(deps): bump the aws group across 1 directory with 6 updates
(#11053)
* fix(misconf): parse Azure flexible server parameters under their own
names (#11072)
* chore(deps): bump the docker group with 2 updates (#11054)
* feat: add RapidFort curated image scanner (#10452)
* feat(java): resolve JAR license URLs to SPDX IDs (Bundle-License, pom
<url>) (#10948)
* refactor(misconf): remove unused Azure expression-related code (#10637)
* fix(server): preserve check aliases and query in uploaded blobs
(#11080)
* fix(java): read artifact properties only from the MANIFEST.MF main
section (#11066)
* fix(terraform): support OpenTofu language block (#10923)
* chore(deps): bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2
(#11063)
* ci: trigger Auto Ready for Review after Test docs (#11045)
* docs: remove trivy-checks from AWS ECR locations (#11044)
* refactor(ubuntu): move EOL version resolution out of loop (#11047)
* fix(python): normalize dependency names in PEP 621 pyproject.toml
(#11050)
* chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#11042)
* chore(deps): bump github.com/nikolalohinski/gonja/v2 to v2.9.0 (#11038)
* fix(terraform): avoid panic when for_each local has unknown object
values (#11019)
* chore(deps): bump the github-actions group across 2 directories with
15 updates (#11028)
* ci(spdx): migrate to Slack notifications (#11032)
* ci(helm): bump Trivy version to 0.73.0 for Trivy Helm Chart 0.25.0
(#11034)
- Update to version 0.73.0 (boo#1276128,
CVE-2026-72817,CVE-2026-72815,CVE-2026-72816):
* release: v0.73.0 [main] (#11012)
* docs: clarify debug logs when version check or telemetry is disabled
(#10984)
* feat(java): support user-defined Maven mirrors in trivy.yaml (#11006)
* chore(deps): bump the common group across 1 directory with 17 updates
(#11025)
* chore(deps): bump the docker group across 1 directory with 2 updates
(#10991)
* chore(deps): bump the aws group across 1 directory with 6 updates
(#10947)
* refactor(alpine): remove type assertion when reading the APKINDEX
archive (#11013)
* chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#10995)
* feat(vex): discover OpenVEX in generic in-toto OCI referrers (#10986)
* refactor(vuln): add OS.Supplier field and unify supplier terminology
(#11007)
* chore(deps): bump github.com/google/cel-go from 0.28.1 to 0.30.0
(#11009)
* fix(vex): reject non-local VEX repository names (#10987)
* fix(vex): handle 304 status code (#10307)
* fix(vuln): don't skip packages covered by a driver's own advisory feed
(#10980)
* fix(conda): avoid panic on an all-operator dependency line (#10955)
* chore: add schema id (#10969)
* feat(vex): native discovery of VEX documents stored as OCI artifacts
(#10932)
* feat: add bounded read helpers (#10974)
* fix(dotnet): identify deps.json root project from dependency graph
(#10954)
* feat(java): read Jenkins plugin manifest licenses (#10939)
* docs: ask contributors to coordinate before starting on an issue
(#10940)
* fix(nodejs): support pnpm workspaces with overlapping packages (#10894)
* ci: create release branch with the App token to bypass the merge queue
rule (#10931)
* chore(deps): bump the common group across 1 directory with 15 updates
(#10892)
* feat(seal): detect no-prefix packages by version suffix (#10911)
* chore(deps): bump the testcontainers group with 2 updates (#10918)
* chore(deps): bump the docker group across 1 directory with 4 updates
(#10919)
* fix(java): set per-file digest for nested JARs (#10855)
* fix(misconf): guard nil Healthcheck when building Dockerfile from
history (#10899)
* ci(helm): bump Trivy version to 0.72.0 for Trivy Helm Chart 0.24.0
(#10908)
* ci(helm): allow trivy team to approve Chart.yaml bumps (#10912)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-312=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
trivy-0.74.0-bp157.2.18.1
References:
https://www.suse.com/security/cve/CVE-2026-72815.html
https://www.suse.com/security/cve/CVE-2026-72816.html
https://www.suse.com/security/cve/CVE-2026-72817.html
https://bugzilla.suse.com/1276128