Описание
Security update for trivy
This update for trivy fixes the following issues
Update to version 0.71.2:
- CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267268).
- CVE-2026-46680: github.com/containerd/containerd/v2/pkg/oci: containerd user ID handling bypass allows runAsNonRoot evasion (bsc#1268356).
- CVE-2026-47262: github.com/containerd/containerd/v2/pkg/oci: Denial of Service (DoS) condition via a maliciously crafted image (bsc#1268440).
- CVE-2026-50195: containerd: fails to validate the image references specified within a checkpoint image's configuration (bsc#1268399).
- CVE-2026-53488: containerd: CRI plugin propagates labels from an image config to a container without validation (bsc#1268400).
- CVE-2026-53489: containerd: CRI plugin restores container.log from a checkpoint image without validating a symlinked path (bsc#1268404).
- CVE-2026-53492: containerd: improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration (bsc#1268403).
Changes for trivy:
- release: v0.71.2 [release/v0.71] (#10871)
- fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)
- chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)
- fix(oci): validate artifact filename
- fix: forward ospkg detector options through ospkg.NewScanner
- fix(vex): load VEX documents from within the repository directory
- fix: surface the original analysis error instead of context cancellation
- ci: expect GitHub App bot as backport PR author
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1267268
- SUSE Bug 1268356
- SUSE Bug 1268399
- SUSE Bug 1268400
- SUSE Bug 1268403
- SUSE Bug 1268404
- SUSE Bug 1268440
- SUSE CVE CVE-2026-44740 page
- SUSE CVE CVE-2026-46680 page
- SUSE CVE CVE-2026-47262 page
- SUSE CVE CVE-2026-50195 page
- SUSE CVE CVE-2026-53488 page
- SUSE CVE CVE-2026-53489 page
- SUSE CVE CVE-2026-53492 page
Описание
Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.
Затронутые продукты
Ссылки
- CVE-2026-44740
- SUSE Bug 1267264
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-46680
- SUSE Bug 1268355
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47262
- SUSE Bug 1268405
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-50195
- SUSE Bug 1268399
Описание
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Затронутые продукты
Ссылки
- CVE-2026-53488
- SUSE Bug 1268400
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-53489
- SUSE Bug 1268404
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-53492
- SUSE Bug 1268403