openSUSE-SU-2026:0312-1: moderate: Security update for trivy

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for trivy
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0312-1
Rating:             moderate
References:         #1276128 
Cross-References:   CVE-2026-72815 CVE-2026-72816 CVE-2026-72817
                   
CVSS scores:
                    CVE-2026-72815 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
                    CVE-2026-72816 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
                    CVE-2026-72817 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:

   This update for trivy fixes the following issues:

   - Update to version 0.74.0:
     * release: v0.74.0 [main] (#11037)
     * chore(deps): update golang.org/x modules (#11094)
     * chore(deps): bump the docker group with 2 updates (#11090)
     * docs: update release branch ruleset instructions (#11093)
     * chore(deps): bump the common group across 1 directory with 7 updates
       (#11086)
     * fix(misconf): unmark cty values outside the evaluation context (#11078)
     * chore(deps): bump the aws group across 1 directory with 6 updates
       (#11053)
     * fix(misconf): parse Azure flexible server parameters under their own
       names (#11072)
     * chore(deps): bump the docker group with 2 updates (#11054)
     * feat: add RapidFort curated image scanner (#10452)
     * feat(java): resolve JAR license URLs to SPDX IDs (Bundle-License, pom
       <url>) (#10948)
     * refactor(misconf): remove unused Azure expression-related code (#10637)
     * fix(server): preserve check aliases and query in uploaded blobs
       (#11080)
     * fix(java): read artifact properties only from the MANIFEST.MF main
       section (#11066)
     * fix(terraform): support OpenTofu language block (#10923)
     * chore(deps): bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2
       (#11063)
     * ci: trigger Auto Ready for Review after Test docs (#11045)
     * docs: remove trivy-checks from AWS ECR locations (#11044)
     * refactor(ubuntu): move EOL version resolution out of loop (#11047)
     * fix(python): normalize dependency names in PEP 621 pyproject.toml
       (#11050)
     * chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#11042)
     * chore(deps): bump github.com/nikolalohinski/gonja/v2 to v2.9.0 (#11038)
     * fix(terraform): avoid panic when for_each local has unknown object
       values (#11019)
     * chore(deps): bump the github-actions group across 2 directories with
       15 updates (#11028)
     * ci(spdx): migrate to Slack notifications (#11032)
     * ci(helm): bump Trivy version to 0.73.0 for Trivy Helm Chart 0.25.0
       (#11034)

   - Update to version 0.73.0 (boo#1276128,
     CVE-2026-72817,CVE-2026-72815,CVE-2026-72816):
     * release: v0.73.0 [main] (#11012)
     * docs: clarify debug logs when version check or telemetry is disabled
       (#10984)
     * feat(java): support user-defined Maven mirrors in trivy.yaml (#11006)
     * chore(deps): bump the common group across 1 directory with 17 updates
       (#11025)
     * chore(deps): bump the docker group across 1 directory with 2 updates
       (#10991)
     * chore(deps): bump the aws group across 1 directory with 6 updates
       (#10947)
     * refactor(alpine): remove type assertion when reading the APKINDEX
       archive (#11013)
     * chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#10995)
     * feat(vex): discover OpenVEX in generic in-toto OCI referrers (#10986)
     * refactor(vuln): add OS.Supplier field and unify supplier terminology
       (#11007)
     * chore(deps): bump github.com/google/cel-go from 0.28.1 to 0.30.0
       (#11009)
     * fix(vex): reject non-local VEX repository names (#10987)
     * fix(vex): handle 304 status code (#10307)
     * fix(vuln): don't skip packages covered by a driver's own advisory feed
       (#10980)
     * fix(conda): avoid panic on an all-operator dependency line (#10955)
     * chore: add schema id (#10969)
     * feat(vex): native discovery of VEX documents stored as OCI artifacts
       (#10932)
     * feat: add bounded read helpers (#10974)
     * fix(dotnet): identify deps.json root project from dependency graph
       (#10954)
     * feat(java): read Jenkins plugin manifest licenses (#10939)
     * docs: ask contributors to coordinate before starting on an issue
       (#10940)
     * fix(nodejs): support pnpm workspaces with overlapping packages (#10894)
     * ci: create release branch with the App token to bypass the merge queue
       rule (#10931)
     * chore(deps): bump the common group across 1 directory with 15 updates
       (#10892)
     * feat(seal): detect no-prefix packages by version suffix (#10911)
     * chore(deps): bump the testcontainers group with 2 updates (#10918)
     * chore(deps): bump the docker group across 1 directory with 4 updates
       (#10919)
     * fix(java): set per-file digest for nested JARs (#10855)
     * fix(misconf): guard nil Healthcheck when building Dockerfile from
       history (#10899)
     * ci(helm): bump Trivy version to 0.72.0 for Trivy Helm Chart 0.24.0
       (#10908)
     * ci(helm): allow trivy team to approve Chart.yaml bumps (#10912)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-312=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      trivy-0.74.0-bp157.2.18.1


References:

   https://www.suse.com/security/cve/CVE-2026-72815.html
   https://www.suse.com/security/cve/CVE-2026-72816.html
   https://www.suse.com/security/cve/CVE-2026-72817.html
   https://bugzilla.suse.com/1276128
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.