SUSE-CU-2026:7242-1: Security update of private-registry/1.2/harbor-trivy-adapter

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 22 07:22:48 UTC 2026


SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7242-1
Container Tags        : private-registry/1.2/harbor-trivy-adapter:1.2.0 , private-registry/1.2/harbor-trivy-adapter:1.2.0-1.62 , private-registry/1.2/harbor-trivy-adapter:latest
Container Release     : 1.62
Severity              : important
Type                  : security
References            : 1266495 1268290 1271658 1271670 CVE-2026-39821 CVE-2026-50151
                        CVE-2026-54411 CVE-2026-56852 
-----------------------------------------------------------------

The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3147-1
Released:    Tue Jul 21 14:44:03 2026
Summary:     Security update for trivy
Type:        security
Severity:    important
References:  1266495,1271658,1271670,CVE-2026-39821,CVE-2026-50151,CVE-2026-56852
This update for trivy fixes the following issues

- Update to version 0.72.0
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495).
- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658).
- CVE-2026-56852: x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271670).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released:    Tue Jul 21 16:50:54 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).


The following package changes have been done:

- pam-1.3.0-150000.6.89.1 updated
- trivy-0.72.0-150000.1.27.1 updated
- harbor-scanner-trivy-0.36.0-150700.1.12 updated
- system-user-harbor-2.15.1-150700.1.20 updated
- container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated


More information about the sle-container-updates mailing list