FlawAtlas
Search the atlas
SUSE-SU-2025:02282-1 Not scored

Security update for umoci

This update for umoci fixes the following issues: Update to umoci v0.5.0. Upstream changelog is available from <https://github.com/opencontainers/umoci/releases/tag/v0.5.0> bsc#1243388 A security flaw was found in the OCI image-spec, where it is possible to cause a blob with one media-type to be interpreted as a different media-type. As umoci is not a registry nor does it handle signatures, this vulnerability had no real impact on umoci but for safety we implemented the now-recommended media-type embedding and verification. CVE-2021-41190 Other changes in this release: * Several large reworks and API-related changes to the umoci's overlayfs support. This is only available to Go API users. * The runtime-spec config.json generated by umoci is updated to be more modern and work properly with modern runc versions. * The default gzip compression blocksize has been adjusted to match Docker. * zstd-compressed images are now fully supported. Users can explcitily request the compression algorithm for newly-generated layers with the --compress option.

Exploit probability Not scored
Published July 11, 2025
Required by Not available
Last source change July 12, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server for SAP Applications 15 SP5 umoci
SUSE:Enterprise Storage 7.1 umoci
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS umoci
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS umoci
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS umoci
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS umoci
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS umoci
SUSE:Linux Enterprise Module for Basesystem 15 SP6 umoci
SUSE:Linux Enterprise Module for Basesystem 15 SP7 umoci
SUSE:Linux Enterprise Server 15 SP3-LTSS umoci
SUSE:Linux Enterprise Server 15 SP4-LTSS umoci
SUSE:Linux Enterprise Server 15 SP5-LTSS umoci
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 umoci
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 umoci
SUSE:Manager Proxy 4.3 umoci
SUSE:Manager Server 4.3 umoci
openSUSE:Leap 15.6 umoci

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:02282-1

This update for umoci fixes the following issues: Update to umoci v0.5.0. Upstream changelog is available from <https://github.com/opencontainers/umoci/releases/tag/v0.5.0> bsc#1243388 A security flaw was found in the OCI image-spec, where it is possible to cause a blob with one media-type to be interpreted as a different media-type. As umoci is not a registry nor does it handle signatures, this vulnerability had no real impact on umoci but for safety we implemented the now-recommended media-type embedding and verification. CVE-2021-41190 Other changes in this release: * Several large reworks and API-related changes to the umoci's overlayfs support. This is only available to Go API users. * The runtime-spec config.json generated by umoci is updated to be more modern and work properly with modern runc versions. * The default gzip compression blocksize has been adjusted to match Docker. * zstd-compressed images are now fully supported. Users can explcitily request the compression algorithm for newly-generated layers with the --compress option.

View original source

05 / REFERENCES

Further evidence