Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21072-1

Опубликовано: 26 июн. 2026
Источник: suse-cvrf

Описание

Security update for trivy

This update for trivy fixes the following issues

Update to version 0.71.2:

  • CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267268).
  • CVE-2026-46680: github.com/containerd/containerd/v2/pkg/oci: containerd user ID handling bypass allows runAsNonRoot evasion (bsc#1268356).
  • CVE-2026-47262: github.com/containerd/containerd/v2/pkg/oci: Denial of Service (DoS) condition via a maliciously crafted image (bsc#1268440).
  • CVE-2026-50195: containerd: fails to validate the image references specified within a checkpoint image's configuration (bsc#1268399).
  • CVE-2026-53488: containerd: CRI plugin propagates labels from an image config to a container without validation (bsc#1268400).
  • CVE-2026-53489: containerd: CRI plugin restores container.log from a checkpoint image without validating a symlinked path (bsc#1268404).
  • CVE-2026-53492: containerd: improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration (bsc#1268403).

Changes for trivy:

  • release: v0.71.2 [release/v0.71] (#10871)
  • fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)
  • chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)
  • fix(oci): validate artifact filename
  • fix: forward ospkg detector options through ospkg.NewScanner
  • fix(vex): load VEX documents from within the repository directory
  • fix: surface the original analysis error instead of context cancellation
  • ci: expect GitHub App bot as backport PR author

Список пакетов

openSUSE Leap 16.0
trivy-0.71.2-160000.1.1

Описание

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки

Описание

unknown


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки

Описание

unknown


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки

Описание

unknown


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки

Описание

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки

Описание

unknown


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки

Описание

unknown


Затронутые продукты
openSUSE Leap 16.0:trivy-0.71.2-160000.1.1

Ссылки