Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for trivy fixes the following issues:
- Update embedded dependencies:
* update x/net to 0.57.0 (boo#1266495, CVE-2026-39821)
* update x/text to 0.40.0 (boo#1271670, CVE-2026-56852)
* update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151)
- Update trivy to version 0.72.0:
* release: v0.72.0 [main] (#10782)
* test: close plugin manager in tests cleanup (#10904)
* Merge commit from fork
* feat(bottlerocket): add vulnerability matching for Bottlerocket OS
(#10893)
* fix(misconf): support github_repository_vulnerability_alerts resource
(#10680)
* feat(java): detect JAR licenses from packaged LICENSE files (#10856)
* fix(nodejs): parse project dependencies from multi-document
pnpm-lock.yaml (#10861)
* fix(server): propagate package repository class in client/server mode
(#10874)
* chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to
2.3.2 (#10888)
*...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-263=1
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
trivy-0.72.0-bp157.2.15.1
https://www.suse.com/security/cve/CVE-2026-39821.html
https://www.suse.com/security/cve/CVE-2026-46680.html
https://www.suse.com/security/cve/CVE-2026-50151.html
https://www.suse.com/security/cve/CVE-2026-54448.html
https://www.suse.com/security/cve/CVE-2026-55092.html
https://www.suse.com/security/cve/CVE-2026-56852.html
https://bugzilla.suse.com/1266495
https://bugzilla.suse.com/1268356
https://bugzilla.suse.com/1269269
https://bugzilla.suse.com/1269271
https://bugzilla.suse.com/1271658
https://bugzilla.suse.com/1271670
Get the latest Linux and open source security news straight to your inbox.