gpp_maybe
Security update for trivy
openSUSE-2026-219
This update for trivy fixes the following issues: - CVE-2026-50195: containerd: fails to validate the image references specified within a checkpoint image's configuration (boo#1268399). - CVE-2026-53488: containerd: CRI plugin propagates labels from an image config to a container without validation (boo#1268400). - CVE-2026-53492: containerd: improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration (boo#1268403). - CVE-2026-53489: containerd: CRI plugin restores container.log from a checkpoint image without validating a symlinked path (boo#1268404). - CVE-2026-47262: trivy: github.com/containerd/containerd/v2/pkg/oci: Denial of Service (DoS) condition via a maliciously crafted image (boo#1268440). - CVE-2026-44740: trivy: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (boo#1267268). - CVE-2026-46680: trivy: github.com/containerd/containerd/v2/pkg/oci: containerd user ID handling bypass allows runAsNonRoot evasion (boo#1268356). - CVE-2026-39821: trivy: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266495). - CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: trivy: golang.org/x/net/html: multiple issues when parsing HTML files (boo#1267047). - CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835: trivy: golang.org/x/crypto/ssh: multiple issues (boo#1266075). - CVE-2026-41506: trivy: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (boo#1264873). - CVE-2026-33814: trivy: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (boo#1265648).
-
Release DateJun 26 2026
-
ReferencesBugzilla: 1264873, 1268356, 1266495, 1266075, 1268403, 1268400, 1268440, 1267268, 1265648, 1267047, 1268399, 1268404
CVEs: CVE-2026-42502, CVE-2026-46598, CVE-2026-53488, CVE-2026-39821, CVE-2026-46597, CVE-2026-25680, CVE-2026-39833, CVE-2026-27136, CVE-2026-46680, CVE-2026-39830, CVE-2026-42508, CVE-2026-39835, CVE-2026-44740, CVE-2026-39828, CVE-2026-39829, CVE-2026-46595, CVE-2026-33814, CVE-2026-41506, CVE-2026-47262, CVE-2026-53492, CVE-2026-50195, CVE-2026-39834, CVE-2026-53489, CVE-2026-39831, CVE-2026-25681, CVE-2026-39827, CVE-2026-42506, CVE-2026-39832 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Package Hub 15.7 ppc64le
-
Packages
SUSE Package Hub 15.7 s390x
-
Packages
SUSE Package Hub 15.7 x86_64
-
Packages
SUSE Package Hub 15.7 aarch64
-
Packages