Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 479
Alerts This Week
Warning Icon 1 479

openSUSE Leap 16.0 trivy Important Privilege Escalation Vuln 2026-21395-1

opensuse
Calendar Grey July 23, 2026
Scroller Opensuse
This OpenSUSE advisory details important updates fixing multiple issues in Trivy, improving security and functionality.
openSUSE has released a security update for trivy addressing three vulnerabilities, which includes fixes for privilege escalation and credential forwarding, available for openSUSE ...

Description

This update for trivy fixes the following issues

- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495).

- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658).

- CVE-2026-56852: trivy: infinite loop on truncated/invalid UTF-8 input (bsc#1271670).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1305=1

Patch

Package List

- openSUSE Leap 16.0:

trivy-0.72.0-160000.2.1

References

* bsc#1266495

* bsc#1271658

* bsc#1271670

References:

* https://www.suse.com/security/cve/CVE-2026-39821.html

* https://www.suse.com/security/cve/CVE-2026-50151.html

* https://www.suse.com/security/cve/CVE-2026-56852.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21395-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.