Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE 2025:0056-1 moderate: trivy security update for multiple issues

opensuse
Calendar Grey February 7, 2025
Dist Opensuse Esm H88
Important security patch for openSUSE available for trivy, addressing various vulnerabilities; update using YaST or zypper immediately!
An update that fixes 8 vulnerabilities is now available

Description

This update for trivy fixes the following issues:

Update to version 0.58.2 (

boo#1234512, CVE-2024-45337, boo#1235265, CVE-2024-45338):

* fix(misconf): allow null values only for tf variables [backport:

release/v0.58] (#8238)

* fix(suse): SUSE - update OSType constants and references for

compatility [backport: release/v0.58] (#8237)

* fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection

via the URL field [backport: release/v0.58] (#8215)

* fix(sbom): attach nested packages to Application [backport:

release/v0.58] (#8168)

* fix(python): skip dev group's deps for poetry [backport:

release/v0.58] (#8158)

* fix(sbom): use root package for `unknown` dependencies (if exists)

[backport: release/v0.58] (#8156)

* chore(deps): bump `golang.org/x/net` from `v0.32.0` to `v0.33.0`

[backport: release/v0.58] (#8142)

* chore(deps): bump `github.com/CycloneDX/cyclonedx-go` from...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-56=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

trivy-0.58.2-bp156.2.6.1

References

https://www.suse.com/security/cve/CVE-2024-34155.html

https://www.suse.com/security/cve/CVE-2024-34156.html

https://www.suse.com/security/cve/CVE-2024-34158.html

https://www.suse.com/security/cve/CVE-2024-3817.html

https://www.suse.com/security/cve/CVE-2024-45337.html

https://www.suse.com/security/cve/CVE-2024-45338.html

https://www.suse.com/security/cve/CVE-2025-21613.html

https://www.suse.com/security/cve/CVE-2025-21614.html

https://bugzilla.suse.com/show_bug.cgi?id=1227010

https://bugzilla.suse.com/show_bug.cgi?id=1234512

https://bugzilla.suse.com/show_bug.cgi?id=1235265

Announcement ID: openSUSE-SU-2025:0056-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here