{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21072-1","published":"2026-06-26T09:25:10Z","modified":"2026-06-30T18:24:30.626245692Z","related":["CVE-2026-44740","CVE-2026-46680","CVE-2026-47262","CVE-2026-50195","CVE-2026-53488","CVE-2026-53489","CVE-2026-53492"],"upstream":["CVE-2026-44740","CVE-2026-46680","CVE-2026-47262","CVE-2026-50195","CVE-2026-53488","CVE-2026-53489","CVE-2026-53492"],"summary":"Security update for trivy","details":"This update for trivy fixes the following issues\n\nUpdate to version 0.71.2:\n\n- CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite\n  loops, panics or resource consumption (bsc#1267268).\n- CVE-2026-46680: github.com/containerd/containerd/v2/pkg/oci: containerd user ID handling bypass allows runAsNonRoot\n  evasion (bsc#1268356).\n- CVE-2026-47262: github.com/containerd/containerd/v2/pkg/oci: Denial of Service (DoS) condition via a maliciously\n  crafted image (bsc#1268440).\n- CVE-2026-50195: containerd: fails to validate the image references specified within a checkpoint image's\n  configuration (bsc#1268399).\n- CVE-2026-53488: containerd: CRI plugin propagates labels from an image config to a container without validation\n  (bsc#1268400).\n- CVE-2026-53489: containerd: CRI plugin restores container.log from a checkpoint image without validating a symlinked\n  path (bsc#1268404).\n- CVE-2026-53492: containerd: improperly trusts Container Device Interface (CDI) annotations found within untrusted\n  checkpoint image metadata during container restoration (bsc#1268403).\n\nChanges for trivy:\n\n * release: v0.71.2 [release/v0.71] (#10871)\n * fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)\n * chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)\n * fix(oci): validate artifact filename\n * fix: forward ospkg detector options through ospkg.NewScanner\n * fix(vex): load VEX documents from within the repository\n   directory\n * fix: surface the original analysis error instead of context\n   cancellation\n * ci: expect GitHub App bot as backport PR author\n","affected":[{"package":{"name":"trivy","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/trivy&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.71.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"trivy":"0.71.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21072-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267268"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268356"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268399"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268403"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268404"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268440"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44740"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47262"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50195"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53488"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53492"}]}