SUSE-CU-2026:7257-1: Security update of private-registry/harbor-trivy-adapter

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Jul 23 07:13:31 UTC 2026


SUSE Container Update Advisory: private-registry/harbor-trivy-adapter
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7257-1
Container Tags        : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.79 , private-registry/harbor-trivy-adapter:latest
Container Release     : 2.79
Severity              : important
Type                  : security
References            : 1252306 1253043 1257463 1266495 1270393 1271658 1271670 CVE-2026-39821
                        CVE-2026-50151 CVE-2026-56852 
-----------------------------------------------------------------

The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released:    Tue Jul 21 09:04:39 2026
Summary:     Recommended update for shadow
Type:        recommended
Severity:    important
References:  1270393
This update for shadow fixes the following issues:

- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3147-1
Released:    Tue Jul 21 14:44:03 2026
Summary:     Security update for trivy
Type:        security
Severity:    important
References:  1266495,1271658,1271670,CVE-2026-39821,CVE-2026-50151,CVE-2026-56852
This update for trivy fixes the following issues

- Update to version 0.72.0
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495).
- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658).
- CVE-2026-56852: x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271670).


The following package changes have been done:

- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- trivy-0.72.0-150000.1.27.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- harbor-scanner-trivy-0.36.0-150700.1.11 updated
- system-user-harbor-2.14.4-150700.1.19 updated
- container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated


More information about the sle-container-updates mailing list