SUSE-CU-2026:7242-1: Security update of private-registry/1.2/harbor-trivy-adapter
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Jul 22 07:22:48 UTC 2026
SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7242-1
Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.0 , private-registry/1.2/harbor-trivy-adapter:1.2.0-1.62 , private-registry/1.2/harbor-trivy-adapter:latest
Container Release : 1.62
Severity : important
Type : security
References : 1266495 1268290 1271658 1271670 CVE-2026-39821 CVE-2026-50151
CVE-2026-54411 CVE-2026-56852
-----------------------------------------------------------------
The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3147-1
Released: Tue Jul 21 14:44:03 2026
Summary: Security update for trivy
Type: security
Severity: important
References: 1266495,1271658,1271670,CVE-2026-39821,CVE-2026-50151,CVE-2026-56852
This update for trivy fixes the following issues
- Update to version 0.72.0
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495).
- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658).
- CVE-2026-56852: x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271670).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released: Tue Jul 21 16:50:54 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1268290,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).
The following package changes have been done:
- pam-1.3.0-150000.6.89.1 updated
- trivy-0.72.0-150000.1.27.1 updated
- harbor-scanner-trivy-0.36.0-150700.1.12 updated
- system-user-harbor-2.15.1-150700.1.20 updated
- container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated
More information about the sle-container-updates
mailing list