SUSE-SU-2025:02282-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-202502282-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02282-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2025:02282-1
Upstream
Related
Published
2025-07-11T08:34:24Z
Modified
2025-07-12T13:01:50.225104Z
Summary
Security update for umoci
Details

This update for umoci fixes the following issues:

Update to umoci v0.5.0. Upstream changelog is available from

https://github.com/opencontainers/umoci/releases/tag/v0.5.0 bsc#1243388

A security flaw was found in the OCI image-spec, where it is possible to cause a blob with one media-type to be interpreted as a different media-type. As umoci is not a registry nor does it handle signatures, this vulnerability had no real impact on umoci but for safety we implemented the now-recommended media-type embedding and verification. CVE-2021-41190

Other changes in this release:

  • Several large reworks and API-related changes to the umoci's overlayfs support. This is only available to Go API users.
  • The runtime-spec config.json generated by umoci is updated to be more modern and work properly with modern runc versions.
  • The default gzip compression blocksize has been adjusted to match Docker.
  • zstd-compressed images are now fully supported. Users can explcitily request the compression algorithm for newly-generated layers with the --compress option.
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP6 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Basesystem 15 SP7 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Server 15 SP3-LTSS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Server 15 SP4-LTSS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Server 15 SP5-LTSS / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 15 SP3 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 15 SP4 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 15 SP5 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Manager Proxy 4.3 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Manager%20Proxy%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Manager Server 4.3 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Manager%20Server%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

SUSE:Enterprise Storage 7.1 / umoci

Package

Name
umoci
Purl
pkg:rpm/suse/umoci&distro=SUSE%20Enterprise%20Storage%207.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}

openSUSE:Leap 15.6 / umoci

Package

Name
umoci
Purl
pkg:rpm/opensuse/umoci&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-150000.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "umoci": "0.5.0-150000.3.15.1"
        }
    ]
}